Answer in brief
CVE-2026-76228 records a High severity (CVSS 8.4) vulnerability in Renovate before 42.68.5 Remote Code Execution via Gradle Wrapper. The current sources do not mark it as known exploited. The current feed maps renovatebot/renovate (generic), renovatebot/renovate (generic), mend/renovate-ce (generic), mend/renovate-ee-server (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps renovatebot/renovate (generic), renovatebot/renovate (generic), mend/renovate-ce (generic), mend/renovate-ee-server (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| renovatebot/renovategeneric | >=32.124.0 <42.68.5 | 42.68.5 |
| renovatebot/renovategeneric | >=0 <13.3.0 | 13.3.0 |
| mend/renovate-cegeneric | >=0 <13.3.0 | 13.3.0 |
| mend/renovate-ee-servergeneric | >=0 <13.3.0 | 13.3.0 |
| mend/renovate-ee-workergeneric | >=0 <13.3.0 | 13.3.0 |
| renovatenpm | >=32.124.0 <42.68.5 | 42.68.5 |
Published upstream
Aug 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 29, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 19, 2026
Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle Wrapper updates, it invokes a wrapper update command via a shell (e.g. /bin/sh -c ... ./gradlew :wrapper --gradle-distribution-url <value>). If an attacker supplies a malicious gradle-wrapper.properties whose distributionUrl contains shell command substitution syntax such as $(...), the shell evaluates it before Gradle parses the URL, resulting in arbitrary command execution in the Renovate runtime. Exploitation requires the attacker to introduce the malicious file into a repository that Renovate scans; the issue occurs even when allowScripts is disabled.
Quoted source text, attributed separately from HOL analysis.