PT-2026-96131 · Gocd · Gocd
CVE-2026-52741
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v4.0
7.5
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GoCD versions 18.3.0 through 26.0.0
Description
Stored cross-site scripting occurs when the server generates unescaped tracking-tool links from commit comments. This happens when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as
JIRA-(.+). An attacker with commit access to a tracked material can insert URI or HTML special characters into a matching commit comment, which is then executed when a victim views the Compare Pipeline page. This can lead to the exposure of privileged user sessions or unauthorized changes performed with the victim's credentials and privileges.Recommendations
Update to version 26.1.0.
As a temporary mitigation, use conservative matchers that do not match special characters or remove the ID capturing group from the Tracking Tool regular expression.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gocd