GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins Stapler: CSRF crumb embedded in generated JavaScript leaks to same-site attackers

CVE-2026-84649Control plane, storage & DevOpscurated

Impact

An HTTP endpoint that serves dynamically generated JavaScript embeds the user's CSRF crumb as a string literal, so anything hosted on the same site as Jenkins can read it and then act as that user. Jenkins deployments commonly serve user-controlled content from the same origin - Allure and other report publishers, workspace artifact browsing - which is precisely the position this needs. If the targeted user is a Jenkins administrator, the attacker gets to perform administrative actions against a controller that holds cluster and registry credentials for the GPU fleet. Affects Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (except 2088.2093.vd7c3e58008a_6), shipped in Jenkins 2.447 through 2.579, LTS 2.452.1 through 2.568.2.

Who can reach it

An attacker who controls a page hosted on the same site as Jenkins, plus a logged-in Jenkins user who visits it. No Jenkins account required for the attacker if same-site content can be planted through artifacts or published reports.

What to do

Upgrade Jenkins to a release shipping fixed Stapler and restart the controller; the record does not name the fixed version. Where practical, serve build artifacts and published reports from a separate origin so same-site content cannot reach the crumb. Short CI outage, no fleet impact.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.