Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p2rf-wpxj-mx2g | Jenkins Credentials Binding Plugin has a path traversal vulnerability |
Thu, 07 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unsanitized File Names in Jenkins Credentials Binding Plugin Allow Arbitrary File Write Leading to Remote Code Execution |
Wed, 06 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins credentials Binding |
|
| CPEs | cpe:2.3:a:jenkins:credentials_binding:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins credentials Binding |
Thu, 30 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins Project
Jenkins Project jenkins Credentials Binding Plugin |
|
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins Credentials Binding Plugin |
Wed, 29 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unsanitized File Names in Jenkins Credentials Binding Plugin Allow Arbitrary File Write Leading to Remote Code Execution |
Wed, 29 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Wed, 29 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-04-29T14:02:37.784Z
Reserved: 2026-04-28T09:24:35.048Z
Link: CVE-2026-42520
Updated: 2026-04-29T13:59:03.887Z
Status : Analyzed
Published: 2026-04-29T14:16:19.067
Modified: 2026-05-06T16:32:41.713
Link: CVE-2026-42520
No data.
OpenCVE Enrichment
Updated: 2026-05-07T15:45:32Z
Github GHSA