Jenkins Plugin Updates Fix Path Traversal and Stored XSS Bugs
ID: cecb2848-9dd5-5193-9fa7-6642cbe63097
STIX ID: report--cecb2848-9dd5-5193-9fa7-6642cbe63097
Feed Name: GBHackers
**Jenkins security advisory:** Seven vulnerabilities were disclosed across popular Jenkins plugins, including a high-severity path traversal in the Credentials Binding Plugin (CVE-2026-42520) that can lead to remote code execution, two high-severity stored XSS issues in the GitHub and HTML Publisher plugins (CVE-2026-42523, CVE-2026-42524), and four medium-severity flaws affecting Script Security, Matrix Authorization Strategy, GitHub Branch Source, and Microsoft Entra ID plugins; administrators are strongly advised to update to the patched plugin versions immediately to secure CI/CD environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
