Executive brief
Jenkins, a popular automation server used for software development, contains a security flaw in how it handles descriptions for offline build agents. An attacker with basic configuration permissions can inject malicious scripts that execute in the browsers of other users, potentially leading to unauthorized access or data theft. This could compromise the integrity of the build environment and sensitive credentials stored within the Jenkins interface.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Jenkins 2.483 through 2.567 and LTS 2.492.1 through 2.555.2. The vulnerability is located in the handling of user-provided descriptions for a generic 'offline cause' for build nodes. The root cause is a failure to properly escape input provided via the `POST config.xml` API. An attacker with 'Agent/Configure' permissions can exploit this by submitting a malicious payload that is subsequently rendered in the Jenkins UI for other users. Successful exploitation allows for the execution of arbitrary JavaScript in the context of the victim's browser session. The issue is resolved in Jenkins version 2.568.
Affected products
- Jenkins Project Jenkins 2.483 through 2.567, LTS 2.492.1 through 2.555.2
Timeline
- 2026-06-10: advisory: Initial advisory publication
- 2026-06-10: disclosed
- 2026-06-12: other: Advisory reviewed and updated