Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier does not perform a permission check in the getReplayScripts MCP tool that returns the replay script of a Pipeline build.
This allows attackers with Item/Read permission to obtain the Pipeline script of jobs.
MCP Server Plugin 0.178.vffe5a_e770f3b_ requires Item/Extended Read permission to return the replay script of a Pipeline build through the getReplayScripts MCP tool.
{
"cwe_ids": [
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-25T19:18:59Z",
"nvd_published_at": "2026-06-24T14:17:36Z",
"severity": "MODERATE"
}