CVE-2026-92131
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal vulnerability, allowing attackers able to configure Pipelines to read files in a resources directory and to delete files in a test directory on the Jenkins controller file system.
| Vendor | jenkins project |
| Product | jenkins pipeline: groovy libraries plugin |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for jenkins project jenkins pipeline: groovy libraries plugin
Be the first to know when new unknown vulnerabilities affecting jenkins project jenkins pipeline: groovy libraries plugin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Jenkins Project / Jenkins Pipeline: Groovy Libraries Plugin
0 โค 805.va_fc79344957d