A AegiFlow
CRITICALCVSS 9.0EPSS 0.3%

CVE-2026-42523

Jenkins GitHub Plugin has an XSS vulnerability

Published
2026-04-29
Modified
2026-08-14
EPSS percentile
21%
Aliases
GHSA-w22p-4x9f-486v
Sources
github-advisory

Summary

In Jenkins GitHub Plugin versions 1.46.0 and earlier, the JavaScript that validates the "GitHub hook trigger for GITScm polling" feature improperly processes the current job URL. This results in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission. GitHub Plugin 1.46.0.1 no longer processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling".

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavencom.coravy.hudson.plugins.github:github1.46.0.1

Remediation: Upgrade to 1.46.0.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.