Junglewise Threat Intelligence

CVE-2026-42523: Jenkins GitHub Plugin stored XSS in job URL validation

CVE-2026-42523 · Severity: critical · CVSS 9 · Published 2026-04-29

Technologies: com.coravy.hudson.plugins.github:github (Maven). Vendors: Maven, Jenkins.

Executive brief

Jenkins GitHub Plugin is a widely-used integration tool that connects Jenkins continuous integration servers with GitHub repositories. A vulnerability in the plugin's webhook validation logic allows authenticated users with basic read permissions to inject malicious JavaScript code that executes in the browsers of other users viewing affected job configurations. This could lead to session hijacking, credential theft, or unauthorized modification of build configurations.

Technical details

The vulnerability is a stored cross-site scripting (CWE-79) flaw in the JavaScript code that validates the "GitHub hook trigger for GITScm polling" feature in Jenkins GitHub Plugin versions prior to 1.46.0.1. The vulnerable component improperly sanitizes the current job URL before inserting it into client-side JavaScript, allowing an authenticated attacker with Overall/Read permission to craft a malicious job URL containing JavaScript payloads. When other users access the job configuration page, the injected script executes in their browser context with the attacker's privileges. The vulnerability requires user interaction (victim must view the affected job page) and low-privilege authenticated access. The fix in version 1.46.0.1 removes the problematic job URL processing entirely from the validation JavaScript.

Affected products

  • Jenkins GitHub Plugin < 1.46.0.1

Timeline

  • 2026-04-29: disclosed: Published by GitHub Advisory Database and NVD
  • 2026-04-29: patched: Version 1.46.0.1 released with fix

References

Related threats