Bug#1126696: gradle-completion: CVE-2026-25063

Emmanuel Bourg ebourg at apache.org
Sun Feb 8 14:39:29 GMT 2026


Control: severity -1 important

A malicious Gradle build file executes arbitrary code and can trivially 
cause harm to the system, with completion enabled or not. I'm 
downgrading the severity because gradle-completion doesn't deserve to be 
removed, the blame is on the user fetching and building an untrusted 
project.



More information about the pkg-java-maintainers mailing list