{"id":"GHSA-rf8w-7c3g-7h3g","summary":"Jenkins GitHub Integration Plugin has a cross-site request forgery (CSRF) vulnerability","details":"Jenkins GitHub Integration Plugin 0.7.3 and earlier does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.\n\nThis vulnerability allows attackers to trigger a build for a pull request.\n\nGitHub Integration Plugin 0.7.4 requires POST requests for the affected HTTP endpoint.","aliases":["CVE-2026-48925"],"modified":"2026-07-01T20:11:28.843675Z","published":"2026-05-27T15:33:27Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-01T19:44:21Z","nvd_published_at":"2026-05-27T15:16:32Z","cwe_ids":["CWE-352"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48925"},{"type":"PACKAGE","url":"https://github.com/KostyaSha/github-integration-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2026-05-27/#SECURITY-3776"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:github-integration-parent","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/github-integration-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.4"}]}],"versions":["0.0.1-beta15","0.0.1-beta16","0.0.1-beta17","0.0.1-rc1","0.0.1-rc2","0.0.1-rc3","0.0.1-rc4","0.0.1-rc5","0.1.0-rc10","0.1.0-rc11","0.1.0-rc12","0.1.0-rc13","0.1.0-rc14","0.1.0-rc15","0.1.0-rc16","0.1.0-rc17","0.1.0-rc18","0.1.0-rc19","0.1.0-rc20","0.1.0-rc21","0.1.0-rc22","0.1.0-rc23","0.1.0-rc24","0.1.0-rc25","0.1.0-rc26","0.1.0-rc27","0.1.0-rc28","0.1.0-rc29","0.1.0-rc6","0.1.0-rc7","0.1.0-rc8","0.1.0-rc9","0.2.0","0.2.0-alpha-1","0.2.0-alpha-2","0.2.0-alpha-3","0.2.0-rc-1","0.2.0-rc-2","0.2.1","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","0.2.8","0.3.0","0.4.0","0.5.0","0.6.1","0.7.0","0.7.1","0.7.2","0.7.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-rf8w-7c3g-7h3g/GHSA-rf8w-7c3g-7h3g.json","last_known_affected_version_range":"\u003c= 0.7.3"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}