Stored Cross-Site Scripting in GoCD by ThoughtWorks
CVE-2026-52741

7.5HIGH

Key Information:

Vendor

Gocd

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-52741?

In versions of GoCD ranging from 18.3.0 to 26.1.0, a stored cross-site scripting vulnerability exists that allows attackers with commit access to manipulate commit comments. By injecting URI or HTML special characters into these comments, particularly when using lenient regular expressions for Tracking Tool integration, attackers can create unescaped links. When an unsuspecting user views the affected Compare Pipeline page, their session can be compromised, potentially granting the attacker unauthorized access to sensitive information or privileges. This vulnerability poses a significant risk, especially in deployments where tracking tools are integrated with lenient matching criteria. The issue has been addressed in GoCD version 26.1.0.

Affected Version(s)

gocd >= 18.3.0, < 26.1.0

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.