Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-93qh-vwrm-c5pw | Jenkins: Stored XSS vulnerability in node offline cause description |
Wed, 17 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | jenkins: Jenkins: Stored Cross-Site Scripting (XSS) via unescaped user-provided description | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 17 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored Cross‑Site Scripting via Config.xml POST API in Jenkins |
Mon, 15 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins |
|
| CPEs | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* |
|
| Vendors & Products |
Jenkins
Jenkins jenkins |
|
| Metrics |
cvssV3_1
|
Wed, 10 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored Cross‑Site Scripting via Config.xml POST API in Jenkins | |
| First Time appeared |
Jenkins Project
Jenkins Project jenkins |
|
| Weaknesses | CWE-79 | |
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins |
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-06-10T13:06:01.921Z
Reserved: 2026-06-09T14:26:44.789Z
Link: CVE-2026-53441
No data.
Status : Analyzed
Published: 2026-06-10T14:16:37.087
Modified: 2026-06-15T18:05:52.100
Link: CVE-2026-53441
OpenCVE Enrichment
Updated: 2026-06-18T02:00:05Z
Github GHSA