{"apiVersion":"1.0","identifier":"CVE-2026-76228","description":"Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle Wrapper updates, it invokes a wrapper update command via a shell (e.g. /bin/sh -c ... ./gradlew :wrapper --gradle-distribution-url <value>). If an attacker supplies a malicious gradle-wrapper.properties whose distributionUrl contains shell command substitution syntax such as $(...), the shell evaluates it before Gradle parses the URL, resulting in arbitrary command execution in the Renovate runtime. Exploitation requires the attacker to introduce the malicious file into a repository that Renovate scans; the issue occurs even when allowScripts is disabled.","publishedAt":"2026-08-19T14:17:49","lastModifiedAt":"2026-08-19T15:18:10","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76228","cvssScore":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.007,"riskScore":0.71,"affectedProduct":"Renovate","affectedVersions":">=32.124.0,<42.68.5","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-76228","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-76228","en":"https://www.redsauce.net/en/cves/CVE-2026-76228","fr":"https://www.redsauce.net/fr/cves/CVE-2026-76228","pt":"https://www.redsauce.net/pt/cves/CVE-2026-76228","de":"https://www.redsauce.net/de/cves/CVE-2026-76228","sk":"https://www.redsauce.net/sk/cves/CVE-2026-76228","el":"https://www.redsauce.net/el/cves/CVE-2026-76228"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-76228"}}