Stored Cross-Site Scripting in Jenkins Gitee Plugin Affects Builds
CVE-2026-92140
Currently unrated
What is CVE-2026-92140?
The Jenkins Gitee Plugin versions 1301.v8957053c7902 and earlier contain a serious vulnerability that allows attackers to exploit stored cross-site scripting (XSS). This occurs due to insufficient sanitization of the sender name from Gitee push webhook payloads in build triggers, potentially allowing unauthorized execution of scripts by crafting specific build triggers via the webhook endpoint.
Affected Version(s)
Jenkins Gitee Plugin 0 <= 1301.v8957053c7902