CVE-2026-48921: Jenkins Pipeline: Groovy Libraries
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.
Affected products
- Jenkins Pipeline: Groovy Libraries: before 798.v5cc688825312 (fixed in 798.v5cc688825312)
Published 2026-05-27. Last modified 2026-06-17.