Volver a los avisos de seguridad

Sitejet Builder 4.13.1-1 — cPanel & WHM Update

Sitejet Builder 4.13.1-1 is a security update that ships an updated build-time library to resolve CVE-2026-40175, a header-injection flaw (CWE-113, CVSS 4.8) in the library the builder was built with. cPanel customers should update the Sitejet Builder package to pick up the rebuilt binary.

High 4.8 CVSS
cPanel

Versiones afectadas

4.13.1-1

Lo que esto significa bajo una licencia de SharedLicense

CWE-113 covers HTTP response splitting — crafted input can inject headers into responses, enabling cache poisoning or cross-site scripting against the affected component.

Sitejet Builder 4.13.1-1

2026 September 17

Security update

Sitejet Builder ships with an updated build-time library to resolve CVE-2026-40175.

For a full list of changes, read the Sitejet Builder change log.

Preguntas frecuentes

What is CVE-2026-40175?
It is a vulnerability (CWE-113 — HTTP response/header injection, CVSS 4.8) in a build-time library that Sitejet Builder shipped with. cPanel rebuilt Sitejet Builder 4.13.1-1 (September 17, 2026) against the fixed library.
Which Sitejet versions are affected?
Sitejet Builder packages before 4.13.1-1. The 4.13.1-1 release marker indicates the rebuilt build with the updated library.
How do I update Sitejet Builder?
Update cPanel packages with sudo /scripts/upcp --force or via the package manager, then confirm the version in WHM's Sitejet section shows 4.13.1-1 or later.
Is CVE-2026-40175 actively exploited?
No exploitation is reported in cPanel's release note, and the severity is moderate (CVSS 4.8). Update on your normal patching cycle rather than as an emergency.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema