High severity8.0NVD Advisory· Published Apr 29, 2026· Updated May 5, 2026
CVE-2026-42524
CVE-2026-42524
Description
Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:htmlpublisherMaven | < 427.1 | 427.1 |
Affected products
2- Range: <=427
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-f8h4-46xv-h7jjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-42524ghsaADVISORY
- www.jenkins.io/security/advisory/2026-04-29/nvdVendor AdvisoryWEB
News mentions
0No linked articles in our index yet.