Sitejet Builder 4.13.1-1 — cPanel & WHM Update
Sitejet Builder 4.13.1-1 is a security update that ships an updated build-time library to resolve CVE-2026-40175, a header-injection flaw (CWE-113, CVSS 4.8) in the library the builder was built with. cPanel customers should update the Sitejet Builder package to pick up the rebuilt binary.
Affected Versions
4.13.1-1
What this means under a SharedLicense license
CWE-113 covers HTTP response splitting — crafted input can inject headers into responses, enabling cache poisoning or cross-site scripting against the affected component.
Sitejet Builder 4.13.1-1
2026 September 17
Security update
Sitejet Builder ships with an updated build-time library to resolve CVE-2026-40175.
For a full list of changes, read the Sitejet Builder change log.
Frequently Asked Questions
What is CVE-2026-40175?
Which Sitejet versions are affected?
How do I update Sitejet Builder?
Is CVE-2026-40175 actively exploited?
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System