GHSA-j927-269r-96xw
GitHub Security Advisory
Jenkins Cppcheck Plugin vulnerable to stored cross-site scripting (XSS)
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on the Jenkins UI.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control report file contents.
Affected Packages
Maven
org.jenkins-ci.plugins:cppcheck
Affected versions:
0
(last affected: 1.26)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.