CVE-2026-48920 Details
Description
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.
A vulnerability in the Jenkins Email Extension Plugin, specifically in versions through 1933.v45cec755423f, allows for arbitrary file read from the Jenkins controller filesystem. This issue arises from the plugin's feature that enables inlining images as base64 in email content by using the data-inline attribute. The plugin does not restrict the URLs that can be used for inlining images, allowing attackers who can control the email content to specify file URLs that reference local files on the Jenkins server.
Users of the Jenkins Email Extension Plugin should update to version 1933.1935.v276319e3cc47, which removes the vulnerable feature. For those who cannot immediately update, it is recommended to explain the use case for the inlining feature in the issue tracker for a possible return of the feature with proper restrictions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2026-05-27/#SECURITY-3705 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-73 | External Control of File Name or Path | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins email extension | <= 1925.v1598902b_58dd 1933.v45cec755423f |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | New CVE Received | [email protected] |