Jenkins Email Extension Plugin 1933.v45cec755423f and earlier includes a feature that allows inlining images as base64 in email content by setting the data-inline attribute. No restrictions are placed on the image URLs that can be inlined.
This allows attackers able to control the email content to specify file: URLs for images to read arbitrary files from the Jenkins controller filesystem.
The feature allowing inlining images as base64 in email content by setting the data-inline attribute is removed from Email Extension Plugin 1933.1935.v276319e3cc47.
{
"cwe_ids": [
"CWE-73"
],
"github_reviewed": true,
"github_reviewed_at": "2026-07-01T19:42:14Z",
"nvd_published_at": "2026-05-27T15:16:31Z",
"severity": "HIGH"
}