๐Ÿ” CVE Alert

CVE-2026-92131

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal vulnerability, allowing attackers able to configure Pipelines to read files in a resources directory and to delete files in a test directory on the Jenkins controller file system.

Vendor jenkins project
Product jenkins pipeline: groovy libraries plugin
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for jenkins project jenkins pipeline: groovy libraries plugin

Be the first to know when new unknown vulnerabilities affecting jenkins project jenkins pipeline: groovy libraries plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Jenkins Project / Jenkins Pipeline: Groovy Libraries Plugin
0 โ‰ค 805.va_fc79344957d

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
jenkins.io: https://www.jenkins.io/security/advisory/2026-09-16/#SECURITY-3796