Vulnerability Bulletins |
CVE-2026-48920 |
|
| Affected software | JENKINS |
| Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-48920 | |






