Cross-Site Scripting in GoCD Continuous Delivery Server
CVE-2026-68919
7HIGH
What is CVE-2026-68919?
The GoCD continuous delivery server suffers from a vulnerability where it fails to properly encode and escape malicious modification comments. This allows users with write access to inject arbitrary HTML or JavaScript into package material comments. When another user views an affected page, this malicious content can execute in their browser session. The issue arises particularly within the Stage Detail, Job/Build Detail, Value Stream Map, and Pipeline History views of GoCD, making it a significant risk for privileged user sessions. Fixes are included in version 26.1.0.
Affected Version(s)
gocd >= 13.3.0, < 26.1.0
