Description
Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger builds via the Jenkins Gitee Plugin webhook endpoint.
Published: 2026-09-16
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting (XSS)
Action: Update Plugin
AI Analysis

Impact

The Jenkins Gitee Plugin version 1301.v8957053c7902 and earlier fails to escape the sender name supplied in Gitee push webhook payloads. The unescaped value is stored in build causes and rendered by the Jenkins UI without sanitization, giving an attacker the ability to embed arbitrary HTML or JavaScript that will execute in the browser of any user who views the affected build details. This stored XSS flaw allows code injection on the Jenkins web interface.

Affected Systems

The flaw affects Jenkins instances that have the Jenkins Gitee Plugin installed, specifically versions up to and including 1301.v8957053c7902. Any Jenkins job configured to trigger builds via the Gitee webhook endpoint can be vulnerable if the webhook payload is not trusted.

Risk and Exploitability

The vulnerability has a CVSS score of 6.8, indicating medium severity. The EPSS score is less than 1%, suggesting a low current exploitation probability. It is not listed in the CISA KEV catalog. Exploitation requires an attacker to influence the push events on a Gitee repository linked to a vulnerable Jenkins job, which can be achieved by controlling or compromising the repository owner. While the risk is moderate, the impact of successful exploitation can be substantial because injected scripts run with the privileges of the browser user viewing the job.

Generated by OpenCVE AI on September 18, 2026 at 06:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Gitee Plugin to a version later than 1301.v8957053c7902 that includes the correct escaping logic.
  • If the plugin is not necessary for your environment, uninstall it to eliminate the attack surface.
  • Configure the Jenkins Gitee Plugin to enforce secret tokens or other authentication on incoming webhook requests so that only authorized pushes can trigger builds.

Generated by OpenCVE AI on September 18, 2026 at 06:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Unescaped Sender Name in Jenkins Gitee Plugin

Thu, 17 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Gitee Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Gitee Plugin

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger builds via the Jenkins Gitee Plugin webhook endpoint.
References

Subscriptions

Jenkins Project Jenkins Gitee Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T18:34:37.415Z

Reserved: 2026-09-15T16:29:44.795Z

Link: CVE-2026-92140

cve-icon Vulnrichment

Updated: 2026-09-16T18:34:29.079Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:15.960

Modified: 2026-09-18T13:46:13.937

Link: CVE-2026-92140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')