VYPR

renovate-ee

by Mend

Source repositories

CVEs (2)

  • CVE-2026-76228MedAug 19, 2026
    risk 0.44cvss 6.7epss 0.01

    Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle Wrapper updates, it invokes a wrapper update command via a shell (e.g.…

  • CVE-2026-76227MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    Renovate versions from 42.68.1 before 42.96.3 and from 43.0.0 before 43.4.4, including the renovate/renovate Docker images, and Mend Renovate CE/EE images (renovate-ce, renovate-ee-server, renovate-ee-worker) from 13.3.0 before 13.6.0, fail to restrict environment variables to…