GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins SonarQube Scanner Plugin: unrestricted URL scheme in dashboard links causes stored XSS

CVE-2026-84665Control plane, storage & DevOpscurated

Impact

Dashboard links built from SonarQube scanner results are not restricted to safe URL schemes, so a javascript: URL can be stored and executed when another user follows the link. An attacker with Item/Configure permission - which many build-owning developers hold - can therefore run script in the browser of a reviewer or administrator on the CI controller. That path leads to session theft on the system that produces the images and model artifacts deployed to GPU nodes. Affects SonarQube Scanner Plugin 2.18.3 and earlier; requires the plugin to be installed.

Who can reach it

Authenticated Jenkins user holding Item/Configure permission, over the network. Exploitation requires a victim to click the poisoned dashboard link.

What to do

Update the SonarQube Scanner Plugin past 2.18.3 per the 2026-09-02 advisory (SECURITY-3989). Plugin update plus controller restart; no GPU node maintenance. Review existing job dashboard links for javascript: URLs before declaring it closed.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.