Vulnerability GHSA-5qh3-hxx9-w26p

High Risk
HIGH RISK
CVSS Score: 8.8
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 24, 2026 at 03:31 PM UTC
Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE
1.0.0 and 1.0.7
1.0.0 and 1.0.7

Summary

Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE

Details

Jenkins OWASP ZAP Plugin 1.0.7 and earlier does not support distributed builds, causing the file operations and build process of its "Automatically build ZAP" feature to be performed on the Jenkins controller rather than on the agent the build is assigned to.

This allows attackers with Item/Configure permission to configure the feature to build an attacker-controlled project, executing arbitrary code on the Jenkins controller and bypassing any restriction confining the build to a specific agent.

As of publication of this advisory, there is no fix.

Timeline

Published
3 months ago
June 24, 2026 at 03:31 PM UTC
Last Modified
2 days ago
September 25, 2026 at 07:30 PM UTC