Executive brief
The Jenkins Email Extension Plugin, which allows Jenkins to send customized email notifications, contains a security flaw that could allow an attacker to read sensitive files from the Jenkins server. By manipulating email content to include specific file references, an attacker can trick the system into embedding the contents of local system files into emails. This could lead to the exposure of configuration data, credentials, or other private information stored on the Jenkins controller.
Technical details
The Jenkins Email Extension Plugin (up to version 1933.v45cec755423f) contains an arbitrary file read vulnerability classified under CWE-73 (External Control of File Name or Path). The plugin includes a feature that inlines images as base64 data in emails when the 'data-inline' attribute is present; however, it lacks validation or restrictions on the source URLs provided. A remote attacker with low privileges (sufficient to control or influence email content) can specify 'file:' URIs to reference arbitrary files on the Jenkins controller's filesystem. The plugin then reads these files and embeds their content into the generated email. The fix, introduced in version 1933.1935.v276319e3cc47, completely removes the vulnerable inlining feature.
Affected products
- Jenkins Email Extension Plugin 1933.v45cec755423f and earlier
Timeline
- 2026-05-27: advisory: Initial advisory published by Jenkins and GitHub
- 2026-05-27: patched: Fixed in version 1933.1935.v276319e3cc47