CVE-2026-42524Disclosure(jenkins / html_publisher)

LOWCVSS 8.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jenkins html_publisher systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • html_publisher

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-29); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
html_publisher

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-29: 2Mentions · 2026-05-07: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-04-29: 2Technical Details · 2026-05-07: 104-2905-07
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-292
Disclosure2
2026-05-071
Patch1
Full discourse3 posts
  • iototsecnews@iototsecnews
    Patch

    Jenkins プラグインの 7 件の脆弱性が FIX:パス・トラバーサルや蓄積型 XSS の不具合を修正 https://iototsecnews.jp/2026/04/30/jenkins-plugin-updates-fix-path-traversal-and-stored-xss-bugs/ 今回の脆弱性は、主に外部から入力されたデータの処理不備が原因で発生しています。特に深刻な CVE-2026-42520 では、ファイル名のサニタイズ (無害化) が不十分だったため、本来アクセスできない場所にファイルを書き込まれるリスクが生じています。また、CVE-2026-42523 や CVE-2026-42524 では、URL などの情報を画面に表示する際のエスケープ処理が不足しており、悪意のスクリプト実行を許してしまいます。その他にも、CVE-2026-42519 や CVE-2026-42522 のように、適切な権限チェックが行われていない設計上の不備も見つかりました。ご利用のチームは、ご注意ください。 #CVE202642519 #CVE202642521 #CVE202642522 #CVE202642523 #CVE202642524 #CVE202642525 #Jenkins #Plugin #Vulnerability

    Post summary

    Jenkins plugin updates have been released to fix path‑traversal and stored XSS vulnerabilities (CVE‑2026‑42520, 42523, 42524, etc.), providing corrective patches that address the identified security flaws.

    01000129
    487 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42524 Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerabil… https://www.cve.org/CVERecord?id=CVE-2026-42524 ----- Traducción: CVE-2026-42524 Jen… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑42524, a stored XSS flaw in Jenkins HTML Publisher Plugin, linking to the CVE record but providing no PoC, exploit code, or patch details.

    0000034
    74 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42524 Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerabil… https://www.cve.org/CVERecord?id=CVE-2026-42524

    Post summary

    CVE-2026-42524 is a stored XSS vulnerability affecting Jenkins HTML Publisher Plugin v427 and earlier due to unescaped job name and URL in legacy wrapper files, as disclosed in the CVE record.

    00000187
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjenkinshtml_publisher-jenkins-

Explore more