GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins Coverage Plugin: unvalidated coverage results ID allows stored XSS in the controller UI

CVSS 8.0CVE-2026-92135Control plane, storage & DevOpscurated

Impact

The Coverage Plugin up to 3.3358.v9487dde48783 does not validate the coverage results ID submitted with a job configuration through the REST API, letting a user with Item/Configure permission store a javascript: scheme URL as the identifier. The payload runs in the browser of anyone who opens that job's coverage report, administrators included, carrying their Jenkins session. This is a separate plugin and a separate fix from the equivalent Warnings Plugin issue, so patching one does not address the other.

Who can reach it

An authenticated Jenkins user with Item/Configure permission submitting a job configuration through the REST API; another user must view the coverage report for the payload to execute.

What to do

Update the Coverage Plugin past 3.3358.v9487dde48783 through the update center and restart the Jenkins controller - controller-only work, no agent or GPU node impact. In the meantime restrict Item/Configure and review coverage results IDs on jobs that were configured via the API.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.