CVE-2026-57303High· 7.1▾ TwilightJenkins Assembla Plugin has an XXE vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.4%
Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when parsing responses from the configured Assembla server.
This allows attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.
As of publication of this advisory, there is no fix.
org.jenkins-ci.plugins:assembla <= 1.4Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57305Medium· 5.4Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability
CVE-2026-57304Medium· 5.4Jenkins Assembla Plugin has a missing permission check
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2026-57301High· 8.8Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE
CVE-2026-57302Medium· 4.3Jenkins FitNesse Plugin stores passwords unencrypted
CVE-2026-57296High· 8.8Jenkins External Workspace Manager Plugin has a path traversal vulnerability