Stored Cross-Site Scripting in Jenkins Gitee Plugin Affects Builds
CVE-2026-92140

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92140?

The Jenkins Gitee Plugin versions 1301.v8957053c7902 and earlier contain a serious vulnerability that allows attackers to exploit stored cross-site scripting (XSS). This occurs due to insufficient sanitization of the sender name from Gitee push webhook payloads in build triggers, potentially allowing unauthorized execution of scripts by crafting specific build triggers via the webhook endpoint.

Affected Version(s)

Jenkins Gitee Plugin 0 <= 1301.v8957053c7902

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.