GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins Customizable Header Plugin: SVG icon config injection yields stored XSS on every page

CVE-2026-84673Control plane, storage & DevOpscurated

Impact

The plugin's appearance configuration can be overwritten through Stapler data binding, letting an attacker set a custom SVG icon containing inline JavaScript. Because the header renders on every Jenkins page, the payload executes in the browser of every user including administrators, making credential and session theft on the build controller straightforward. A Jenkins administrator session is the key to the pipelines that build and publish what runs on the GPU nodes. Affects Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier; only clusters that actually installed this plugin are exposed.

Who can reach it

Authenticated low-privileged Jenkins user who can reach the controller over the network and submit the data-bound configuration. Administrator victims are hit passively when they load any Jenkins page.

What to do

The 2026-09-02 advisory (SECURITY-4104) does not list a fixed release in the record here; if no fixed version is available, uninstall or disable the Customizable Header Plugin and reset its appearance configuration. Either way it is a plugin change plus a controller restart - no GPU node maintenance.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.