CVE-2026-84665 PUBLISHED

Assigner: jenkins
Reserved: 01.09.2026 Published: 02.09.2026 Updated: 02.09.2026

Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the javascript: scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Product Status

Vendor Jenkins Project
Product Jenkins SonarQube Scanner Plugin
Versions Default: unaffected
  • affected from 0 to 2.18.3 (incl.)

References