logo

Jenkins Plugin Updates Fix Path Traversal and Stored XSS Bugs

ID: cecb2848-9dd5-5193-9fa7-6642cbe63097

STIX ID: report--cecb2848-9dd5-5193-9fa7-6642cbe63097

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Divya

...
...

**Jenkins security advisory:** Seven vulnerabilities were disclosed across popular Jenkins plugins, including a high-severity path traversal in the Credentials Binding Plugin (CVE-2026-42520) that can lead to remote code execution, two high-severity stored XSS issues in the GitHub and HTML Publisher plugins (CVE-2026-42523, CVE-2026-42524), and four medium-severity flaws affecting Script Security, Matrix Authorization Strategy, GitHub Branch Source, and Microsoft Entra ID plugins; administrators are strongly advised to update to the patched plugin versions immediately to secure CI/CD environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.