Groovy Libraries Plugin for Jenkins Exposes Path Traversal Vulnerability
CVE-2026-92131

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92131?

The Groovy Libraries Plugin for Jenkins prior to version 805.va_fc79344957d is susceptible to a path traversal vulnerability. This occurs because the plugin does not enforce restrictions on the library path specified in the library Pipeline step, permitting access to paths outside the intended source code management (SCM) checkout. As a result, malicious actors who configure Pipelines may exploit this flaw to access sensitive files within the resources directory or potentially delete files from the Jenkins controller's test directory.

Affected Version(s)

Jenkins Pipeline: Groovy Libraries Plugin 0 <= 805.va_fc79344957d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.