GHSA-fxxf-w25w-mcx2

Suggest an improvement
Source
https://github.com/advisories/GHSA-fxxf-w25w-mcx2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fxxf-w25w-mcx2/GHSA-fxxf-w25w-mcx2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fxxf-w25w-mcx2
Aliases
Published
2026-05-27T15:33:26Z
Modified
2026-07-01T19:56:31Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Jenkins Credentials Binding Plugin does not properly sanitize file names for file and zip file credentials
Details

Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials.

This allows attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem. If Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node, this can lead to remote code execution.

Credentials Binding Plugin 725.ve52b_2328a_fde improves sanitization of the file name provided for file and zip file credentials, preventing path traversal.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-01T19:41:25Z",
    "nvd_published_at":  "2026-05-27T15:16:31Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:credentials-binding

Package

Name
org.jenkins-ci.plugins:credentials-binding
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/credentials-binding

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
725.ve52b

Affected versions

1.*
1.0-beta-1
1.0
1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8
1.9
1.10
1.11
1.12
1.13
1.14
1.15
1.16
1.17
1.18
1.19
1.20
1.20.1
1.21
1.22
1.23
1.24
1.24.1
1.25
1.26
1.27
1.27.1
523.*
523.vd859a_4b_122e6
523.525.vb_72269281873
604.*
604.vb_64480b_c56ca_
621.*
621.v58c0fb_d285a_c
626.*
626.v8d9034b_8ea_cc
631.*
631.v861c06d062b_4
636.*
636.v55f1275c7b_27
642.*
642.v737c34dea_6c2
657.*
657.v2b_19db_7d6e6d
677.*
677.vdc9d38cb_254d
679.*
679.v6288482e873c
681.*
681.vf91669a_32e45
687.*
687.v619cb_15e923f
687.689.v1a_f775332fc9
696.*
696.v256688029804
702.*
702.vfe613e537e88
717.*
717.v951d49b_5f3a_a_
719.*
719.v80e905ef14eb_
720.*
720.v3f6decef43ea_

Database specific

last_known_affected_version_range
"<= 720.v3f6decef43ea"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fxxf-w25w-mcx2/GHSA-fxxf-w25w-mcx2.json"