CVE-2026-42523Disclosure(jenkins / github)

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jenkins github systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • github

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
github

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-29: 1Mentions · 2026-05-07: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-07: 104-2905-07
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-291
Disclosure1
2026-05-071
Patch1
Full discourse2 posts
  • iototsecnews@iototsecnews
    Patch

    Jenkins プラグインの 7 件の脆弱性が FIX:パス・トラバーサルや蓄積型 XSS の不具合を修正 https://iototsecnews.jp/2026/04/30/jenkins-plugin-updates-fix-path-traversal-and-stored-xss-bugs/ 今回の脆弱性は、主に外部から入力されたデータの処理不備が原因で発生しています。特に深刻な CVE-2026-42520 では、ファイル名のサニタイズ (無害化) が不十分だったため、本来アクセスできない場所にファイルを書き込まれるリスクが生じています。また、CVE-2026-42523 や CVE-2026-42524 では、URL などの情報を画面に表示する際のエスケープ処理が不足しており、悪意のスクリプト実行を許してしまいます。その他にも、CVE-2026-42519 や CVE-2026-42522 のように、適切な権限チェックが行われていない設計上の不備も見つかりました。ご利用のチームは、ご注意ください。 #CVE202642519 #CVE202642521 #CVE202642522 #CVE202642523 #CVE202642524 #CVE202642525 #Jenkins #Plugin #Vulnerability

    Post summary

    The notice announces that seven Jenkins plugin vulnerabilities, including path traversal and stored XSS issues, have been fixed, detailing the technical nature of each flaw.

    01000129
    487 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42523 Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger fo… https://www.cve.org/CVERecord?id=CVE-2026-42523

    Post summary

    The statement announces that Jenkins GitHub Plugin 1.46.0 and earlier have a flaw where job URLs are improperly handled in JavaScript validation, as documented in CVE-2026-42523.

    01000130
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjenkinsgithub-jenkins-

Explore more