PT-2026-44013 · Jenkins · Email Extension Plugin

CVE-2026-48920

·

Published

2026-05-27

·

Updated

2026-05-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Email Extension Plugin versions prior to 1933.v45cec755423f
Description The plugin allows inlining images as base64 in email content by setting the data-inline attribute. Because there are no restrictions on the image URLs that can be inlined, attackers who can control the email content can specify file: URLs for images to read arbitrary files from the Jenkins controller filesystem.
Recommendations Update to a version later than 1933.v45cec755423f.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48920
GHSA-MQ58-M26G-46GP

Affected Products

Email Extension Plugin