cbcvebase.
CVE-2026-42523
published 2026-04-29

CVE-2026-42523: Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook…

critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.

Affected

14 ranges
VendorProductVersion rangeFixed in
jenkinscredentials_binding
jenkinscredentials_binding_plugin
jenkinsgithub< 1.46.0.11.46.0.1
jenkinsgithub
jenkinsgithub_branch_source
jenkinsgithub_branch_source_plugin
jenkinsgithub_plugin
jenkinshtml_publisher
jenkinshtml_publisher_plugin
jenkinsmatrix_authorization_strategy
jenkinsmatrix_authorization_strategy_plugin
jenkinsscript_security
jenkinsscript_security_plugin
jenkins_projectjenkins_github_plugin<= 1.46.0