Description
Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal vulnerability, allowing attackers able to configure Pipelines to read files in a resources directory and to delete files in a test directory on the Jenkins controller file system.
Published: 2026-09-16
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Path Traversal enabling unauthorized file read and deletion on the Jenkins controller
Action: Apply Patch
AI Analysis

Impact

The Groovy Libraries Plugin in Jenkins Pipeline allows a library step to specify any file path. In versions up to 805.va_fc79344957d the plugin does not enforce that the path is within the SCM checkout; it follows symbolic links that can point outside the workspace. This pathname traversal flaw enables a user who can configure pipeline scripts to read arbitrary files from the Jenkins controller’s file system and delete files in non‑workspace directories, compromising confidentiality and integrity.

Affected Systems

Jenkins Pipeline Groovy Libraries Plugin 805.va_fc79344957d and earlier. These versions are part of the Jenkins Project (Jenkins Pipeline) plugin set used for building continuous‑integration pipelines. Any Jenkins installation that has these plugin versions installed is vulnerable. The vulnerability does not, however, affect newer releases past 805.va_fc79344957d.

Risk and Exploitability

The CVSS base score of 4.2 indicates moderate severity. The EPSS score of less than 1% reflects a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The attack can be carried out only by users who have the authority to author or modify pipeline code, so it is inferred that the attacker must have at least pipeline configuration privileges on the Jenkins controller. Once privileged, the attacker can supply a library path that resolves outside the SCM checkout, read sensitive files, or delete files in arbitrary directories.

Generated by OpenCVE AI on September 18, 2026 at 05:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Groovy Libraries Plugin to the latest release that restricts library paths to the SCM workspace
  • Configure Jenkins pipeline steps to use only relative library paths and disable symbolic link traversal
  • Audit existing pipelines for permitted library paths and remove any that could resolve to external directories

Generated by OpenCVE AI on September 18, 2026 at 05:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in Jenkins Pipeline Groovy Libraries Plugin Allows Read and Delete of Controller Files

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Pipeline Groovy Libraries Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Pipeline Groovy Libraries Plugin

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal vulnerability, allowing attackers able to configure Pipelines to read files in a resources directory and to delete files in a test directory on the Jenkins controller file system.
References

Subscriptions

Jenkins Project Jenkins Pipeline Groovy Libraries Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-16T19:45:13.746Z

Reserved: 2026-09-15T16:29:44.794Z

Link: CVE-2026-92131

cve-icon Vulnrichment

Updated: 2026-09-16T19:44:58.473Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:15.113

Modified: 2026-09-18T13:46:13.937

Link: CVE-2026-92131

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:15:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')