CVE-2026-48920
Received
Received - Intake
Email File Read Vulnerability in Jenkins Email Extension Plugin
Publication date: 2026-05-27
Last updated on: 2026-05-28
Assigner: Jenkins Project
Description
Description
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jenkins | email_extension | to 1925.v1598902b_58dd (inc) |
| jenkins | email_extension | 1933.v45cec755423f |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-73 | The product allows user input to control or influence paths or file names that are used in filesystem operations. |