Impact
GoCD, a continuous delivery server, has a stored XSS flaw that occurs when a user with write access to a tracked material submits a forged material modification comment containing malicious HTML or JavaScript. The comment content is rendered without proper encoding on the Stage Detail, Job/Build Detail, Value Stream Map, and Pipeline History pages. Because the comment can emulate the special trackback format used by package materials, any user who later views one of these pages is exposed to script execution in the context of their browser session.
Affected Systems
The vulnerability affects GoCD releases from 13.3.0 up through 26.0.x inclusive. It was resolved in version 26.1.0; any installation older than that is impacted. The attack surface is limited to pages that display material modification comments, meaning that only users that can view Stage Detail, Job/Build Detail, Value Stream Map or Pipeline History are at risk if a malicious comment exists.
Risk and Exploitability
The CVSS score of 7 indicates a high severity due to the potential for client‑side code execution and credential compromise. Exploitation requires the attacker to create or alter a material comment with write permissions and then entice a victim to view a rendered page. As the flaw is not listed in the CISA KEV catalog and no EPSS data is available, the current exploitation probability is uncertain, but organizations should treat it as a likely internal threat, especially in environments where users routinely review pipeline or material change logs.
OpenCVE Enrichment