CVE-2026-48925 PUBLISHED

Assigner: jenkins
Reserved: 26.05.2026 Published: 27.05.2026 Updated: 27.05.2026

A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull request.

Product Status

Vendor Jenkins Project
Product Jenkins GitHub Integration Plugin
Versions Default: unaffected
  • affected from 0 to 0.7.3 (incl.)

References