Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.
Metrics
Affected Vendors & Products
References
History
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-73 | |
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-05-27T15:43:07.808Z
Reserved: 2026-05-26T14:50:46.813Z
Link: CVE-2026-48920
Updated: 2026-05-27T15:43:00.473Z
Status : Received
Published: 2026-05-27T15:16:31.647
Modified: 2026-05-27T17:16:42.663
Link: CVE-2026-48920
No data.
OpenCVE Enrichment
No data.