Groovy Libraries Plugin for Jenkins Exposes Path Traversal Vulnerability
CVE-2026-92131
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-92131?
The Groovy Libraries Plugin for Jenkins prior to version 805.va_fc79344957d is susceptible to a path traversal vulnerability. This occurs because the plugin does not enforce restrictions on the library path specified in the library Pipeline step, permitting access to paths outside the intended source code management (SCM) checkout. As a result, malicious actors who configure Pipelines may exploit this flaw to access sensitive files within the resources directory or potentially delete files from the Jenkins controller's test directory.
Affected Version(s)
Jenkins Pipeline: Groovy Libraries Plugin 0 <= 805.va_fc79344957d