Feed/CVE-2026-48925
CVE-2026-48925MEDIUMCVSS 4.3

Jenkins GitHub Integration Plugin has a cross-site request forgery (CSRF) vulnerability

Published May 27, 2026·Updated Jul 1, 2026

NVD Description

Jenkins GitHub Integration Plugin 0.7.3 and earlier does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability. This vulnerability allows attackers to trigger a build for a pull request. GitHub Integration Plugin 0.7.4 requires POST requests for the affected HTTP endpoint.

Affected Packages (1)

org.jenkins-ci.plugins:github-integration-parentMAVEN
Fixed in = 0.7.3

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free