High severity8.8NVD Advisory· Published May 27, 2026· Updated Jun 17, 2026
CVE-2026-48920
CVE-2026-48920
Description
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as base64 in email content by setting the data-inline attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify file: URLs for images to read arbitrary files from the Jenkins controller filesystem.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:email-extMaven | < 1933.1935.v276319e3cc47 | 1933.1935.v276319e3cc47 |
Affected products
4<=1933.v45cec755423f+ 1 more
- (no CPE)range: <=1933.v45cec755423f
- (no CPE)range: <=1933.v45cec755423f
cpe:2.3:a:jenkins:email_extension:*:*:*:*:*:jenkins:*:*+ 1 more
- cpe:2.3:a:jenkins:email_extension:*:*:*:*:*:jenkins:*:*range: <=1925.v1598902b_58dd
- cpe:2.3:a:jenkins:email_extension:1933.v45cec755423f:*:*:*:*:jenkins:*:*
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-mq58-m26g-46gpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-48920ghsaADVISORY
- www.jenkins.io/security/advisory/2026-05-27/nvdVendor AdvisoryWEB
News mentions
2- Jenkins Security Advisory: 13 CVEs Across 11 Plugins Disclosed May 2026Vypr Intelligence · May 27, 2026
- Jenkins Security Advisory 2026-05-27Jenkins Security Advisories · May 27, 2026