Description
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-73 | |
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-05-27T15:43:07.808Z
Reserved: 2026-05-26T14:50:46.813Z
Link: CVE-2026-48920
Updated: 2026-05-27T15:43:00.473Z
Status : Received
Published: 2026-05-27T15:16:31.647
Modified: 2026-05-27T15:16:31.647
Link: CVE-2026-48920
No data.
OpenCVE Enrichment
No data.
Weaknesses