Intel

AIKIDO-2026-24862

sonar is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)CVE-2026-84665 Published Today

88

High Risk

This Affects:

JAVAsonar
0.0.1 - 2.18.3
Fixed in 2.19.0
Are you affected? Scan for Free

TL;DR

SonarQube Scanner Plugin allows javascript: URLs in dashboard links derived from scanner results. Attackers with Item/Configure permission can persist script URLs that execute when rendered, resulting in stored cross-site scripting. The fix restricts dashboard URL schemes to http and https and stops rendering persisted disallowed schemes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users with Item/Configure permission can control SonarQube scanner result links.

Background info

sonar is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 2.18.3.

How to fix this

Upgrade the org.jenkins-ci.plugins:sonar library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform