GHSA-mq58-m26g-46gp

Suggest an improvement
Source
https://github.com/advisories/GHSA-mq58-m26g-46gp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-mq58-m26g-46gp/GHSA-mq58-m26g-46gp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mq58-m26g-46gp
Aliases
Published
2026-05-27T15:33:26Z
Modified
2026-07-01T19:56:31Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Jenkins Email Extension Plugin: Attackers able to control email content may specify `file:` URLs for images to read arbitrary files from Jenkins controller filesystem
Details

Jenkins Email Extension Plugin 1933.v45cec755423f and earlier includes a feature that allows inlining images as base64 in email content by setting the data-inline attribute. No restrictions are placed on the image URLs that can be inlined.

This allows attackers able to control the email content to specify file: URLs for images to read arbitrary files from the Jenkins controller filesystem.

The feature allowing inlining images as base64 in email content by setting the data-inline attribute is removed from Email Extension Plugin 1933.1935.v276319e3cc47.

Database specific
{
    "cwe_ids":  [
        "CWE-73"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-01T19:42:14Z",
    "nvd_published_at":  "2026-05-27T15:16:31Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:email-ext

Package

Name
org.jenkins-ci.plugins:email-ext
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/email-ext

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1933.1935.v276319e3cc47

Affected versions

2.*
2.11
2.12
2.13
2.14
2.14.1
2.15
2.16
2.18
2.19
2.20
2.21
2.22
2.24.1
2.25
2.27
2.27.1
2.28
2.29
2.30
2.30.1
2.30.2
2.31
2.32
2.33
2.34
2.35
2.35.1
2.36
2.37
2.37.1
2.37.2
2.37.2.2
2.38
2.38.1
2.38.2
2.39
2.39.3
2.40-beta
2.40
2.40.1
2.40.2
2.40.3
2.40.4
2.40.5
2.41
2.41.2
2.41.3
2.42
2.43
2.44
2.45
2.46
2.47
2.50
2.51
2.52
2.53
2.54
2.55
2.56
2.57
2.57.1
2.57.2
2.58
2.59
2.60
2.61
2.62
2.62.1
2.63
2.64
2.65
2.66
2.68
2.68.1
2.68.2
2.69
2.69.1
2.69.2
2.71
2.72
2.73
2.74
2.75
2.76
2.77
2.78
2.79
2.80
2.81
2.82
2.83
2.84
2.85
2.86
2.87
2.88
2.89
2.89.0.1
2.89.0.2
2.89.1
2.90
2.91
2.92
2.93
2.93.1
2.94
2.95
2.96
2.96.1
2.97
2.98
2.99
2.100
2.101
2.102
2.103
2.104
2.105
1806.*
1806.v856a_01a_fa_39a_
1814.*
1814.v404722f34263
1844.*
1844.v3ea_a_b_842374a_
1849.*
1849.v6dd03b_f6e423
1851.*
1851.v2b_5345e6272d
1855.*
1855.vd9e491cb_de1e
1861.*
1861.vdb_d991590994
1866.*
1866.v14fa_6d201654
1876.*
1876.v28d8d38315b_d
1911.*
1911.v19b_8e86f9815
1916.*
1916.vc954a_f86ff21
1922.*
1922.v5c93c9e80a_f9
1925.*
1925.v1598902b_58dd
1933.*
1933.v45cec755423f

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-mq58-m26g-46gp/GHSA-mq58-m26g-46gp.json"