VYPR
High severity8.8NVD Advisory· Published May 27, 2026· Updated Jun 17, 2026

CVE-2026-48920

CVE-2026-48920

Description

Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as base64 in email content by setting the data-inline attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify file: URLs for images to read arbitrary files from the Jenkins controller filesystem.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:email-extMaven
< 1933.1935.v276319e3cc471933.1935.v276319e3cc47

Affected products

4
  • <=1933.v45cec755423f+ 1 more
    • (no CPE)range: <=1933.v45cec755423f
    • (no CPE)range: <=1933.v45cec755423f
  • cpe:2.3:a:jenkins:email_extension:*:*:*:*:*:jenkins:*:*+ 1 more
    • cpe:2.3:a:jenkins:email_extension:*:*:*:*:*:jenkins:*:*range: <=1925.v1598902b_58dd
    • cpe:2.3:a:jenkins:email_extension:1933.v45cec755423f:*:*:*:*:jenkins:*:*

Patches

Vulnerability mechanics

References

3

News mentions

2