CVE-2026-52741: GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages

Published Sep 21, 2026
·
Updated

GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(.+). An attacker with commit access to a tracked material can place URI or HTML special characters in a matching commit comment, causing stored cross-site scripting when a victim views an affected Compare Pipeline page. Deployments without Tracking Tool integration, without an ID capturing group, or with conservative matchers that cannot match special characters are not affected. Successful exploitation can expose a privileged user session or allow changes using the victim's credentials and privileges. This issue is fixed in version 26.1.0.

Affected Software

1 affected component
GoCD GoCD>=18.3.0<26.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GoCD to a version that resolves this vulnerability.

    Fixed in 26.1.0

Event History

Sep 21, 2026
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Affected deployments run GoCD versions from 18.3.0 up to, but not including, 26.1.0 and use Tracking Tool integration with an ID capturing group in a lenient regular expression. Deployments without Tracking Tool integration, without an ID capturing group, or using conservative matchers that cannot match special characters are not affected.

2

What access does an attacker need to exploit it?

The attacker needs commit access to a tracked material. They must place URI or HTML special characters in a commit comment that matches the configured Tracking Tool regular expression.

3

When is the malicious content triggered?

The stored script can execute when a victim views an affected Compare Pipeline page. Impact depends on the victim's privileges and can include exposure of their session or actions performed with their credentials.

4

What is the available remediation?

Upgrade GoCD to version 26.1.0, which fixes the issue. If upgrading is not immediately possible, avoid lenient Tracking Tool regular expressions with ID capturing groups that can match special characters.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203