CVE-2026-48920: Emailext Extendedemailpublisherdescriptor Java Cwe 000 Cve 2026 48920
The Jenkins plugin descriptor is missing Stapler form validation methods for user-controllable attachment patterns. Without these checks, the UI fails to warn or prevent users from embedding path traversal indicators ('..') or absolute paths, leading to arbitrary file reads when the plugin processes the patterns.
greprules fetch cve-2026-48920-emailext-extendedemailpublisherdescriptor-java-cwe-000-cve-2026-48920 --engine opengrepDescription
The Jenkins plugin descriptor is missing Stapler form validation methods for user-controllable attachment patterns. Without these checks, the UI fails to warn or prevent users from embedding path traversal indicators ('..') or absolute paths, leading to arbitrary file reads when the plugin processes the patterns.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.