9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Description
Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.
AI Analysis
Stored cross-site scripting (XSS) vulnerability in Jenkins GitHub Plugin
Basic Information
ID
CVE-2026-42523
Source
jenkins
Published
Apr 29, 2026 at 13:31
Modified
Apr 29, 2026 at 14:29
Affected Product
Vendor
Jenkins Project
Product
Jenkins GitHub Plugin
Version
1.46.0
Affected Versions
Jenkins Project Jenkins GitHub Plugin 0
CWE Classification
AI Assessment
AI Score
9 / 10
AI Severity
Critical
Vendor
Jenkins Project
Product
Jenkins GitHub Plugin
Version
1.46.0 and earlier