PT-2026-35917 · Jenkins · Github Plugin+1
Dqh1
·
Published
2026-04-29
·
Updated
2026-05-05
·
CVE-2026-42523
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins GitHub Plugin versions prior to 1.46.1
Description
Improper processing of the current job URL within the JavaScript used to validate the "GitHub hook trigger for GITScm polling" feature allows non-anonymous attackers with Overall/Read permission to execute a stored cross-site scripting (XSS) attack. XSS is a flaw where malicious scripts are injected into trusted websites.
Recommendations
Update to a version later than 1.46.0.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Plugin
Jenkins