logo

High-Severity RCE and XSS Flaws Found in Popular CI/CD Jenkins Plugins

ID: 8f616530-6a57-557f-af89-2c4233846ee9

STIX ID: report--8f616530-6a57-557f-af89-2c4233846ee9

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Ddos

...
...

Jenkins published an advisory describing multiple plugin vulnerabilities—notably a high-severity path traversal in the Credentials Binding plugin that can lead to remote code execution, and stored XSS flaws in the GitHub and HTML Publisher plugins—plus several medium-severity issues (unsafe deserialization, missing permission checks, open redirect). Administrators are urged to apply the listed plugin updates immediately to mitigate widespread CI/CD exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.