Jenkins Applitools Eyes Plugin vulnerable to XSS through its Build page
High severity
GitHub Reviewed
Published
Jul 9, 2025
to the GitHub Advisory Database
•
Updated Jul 9, 2025
Package
Affected versions
<= 1.16.5
Patched versions
1.16.6
Description
Published by the National Vulnerability Database
Jul 9, 2025
Published to the GitHub Advisory Database
Jul 9, 2025
Reviewed
Jul 9, 2025
Last updated
Jul 9, 2025
Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Applitools Eyes Plugin 1.16.6 rejects Applitools URLs that contain HTML metacharacters.
References