PT-2026-93774 · Jenkins · Pipeline: Groovy Libraries Plugin
CVE-2026-92131
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Pipeline: Groovy Libraries Plugin versions prior to 805.va fc79344957d
Description
An issue exists where the library path provided to the library Pipeline step is not restricted to a relative path within the SCM checkout. Additionally, the plugin follows symbolic links to locations outside of the SCM checkout during library retrieval. This leads to a path traversal—a method used to access files and directories that are stored outside the web root folder—allowing attackers who can configure Pipelines to read files in a resources directory and delete files in a test directory on the Jenkins controller file system.
Recommendations
Update Jenkins Pipeline: Groovy Libraries Plugin to a version later than 805.va fc79344957d.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pipeline: Groovy Libraries Plugin