Back to search
CVE-2026-42523
Published: Apr 29, 2026
Modified: Apr 29, 2026
PUBLISHED
Description
Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins GitHub Plugin | affected 0 - <= 1.46.0 |
References
Jenkins Security Advisory 2026-04-29
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now