Stored Cross-Site Scripting in GoCD by ThoughtWorks
CVE-2026-52741
What is CVE-2026-52741?
In versions of GoCD ranging from 18.3.0 to 26.1.0, a stored cross-site scripting vulnerability exists that allows attackers with commit access to manipulate commit comments. By injecting URI or HTML special characters into these comments, particularly when using lenient regular expressions for Tracking Tool integration, attackers can create unescaped links. When an unsuspecting user views the affected Compare Pipeline page, their session can be compromised, potentially granting the attacker unauthorized access to sensitive information or privileges. This vulnerability poses a significant risk, especially in deployments where tracking tools are integrated with lenient matching criteria. The issue has been addressed in GoCD version 26.1.0.
Affected Version(s)
gocd >= 18.3.0, < 26.1.0
