PT-2026-96131 · Gocd · Gocd

CVE-2026-52741

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

7.5

High

VectorAV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GoCD versions 18.3.0 through 26.0.0
Description Stored cross-site scripting occurs when the server generates unescaped tracking-tool links from commit comments. This happens when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(.+). An attacker with commit access to a tracked material can insert URI or HTML special characters into a matching commit comment, which is then executed when a victim views the Compare Pipeline page. This can lead to the exposure of privileged user sessions or unauthorized changes performed with the victim's credentials and privileges.
Recommendations Update to version 26.1.0. As a temporary mitigation, use conservative matchers that do not match special characters or remove the ID capturing group from the Tracking Tool regular expression.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52741
GHSA-HJ3C-Q23M-FXCG

Affected Products

Gocd