Cross-Site Scripting in GoCD Continuous Delivery Server
CVE-2026-68919

7HIGH

Key Information:

Vendor

Gocd

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-68919?

The GoCD continuous delivery server suffers from a vulnerability where it fails to properly encode and escape malicious modification comments. This allows users with write access to inject arbitrary HTML or JavaScript into package material comments. When another user views an affected page, this malicious content can execute in their browser session. The issue arises particularly within the Stage Detail, Job/Build Detail, Value Stream Map, and Pipeline History views of GoCD, making it a significant risk for privileged user sessions. Fixes are included in version 26.1.0.

Affected Version(s)

gocd >= 13.3.0, < 26.1.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.