{"id":"GHSA-mpff-xhg4-vr45","summary":"Jenkins MCP Server Plugin missing a permission check","details":"Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier does not perform a permission check in the getReplayScripts MCP tool that returns the replay script of a Pipeline build.\n\nThis allows attackers with Item/Read permission to obtain the Pipeline script of jobs.\n\nMCP Server Plugin 0.178.vffe5a_e770f3b_ requires Item/Extended Read permission to return the replay script of a Pipeline build through the getReplayScripts MCP tool.","aliases":["CVE-2026-57300"],"modified":"2026-09-25T19:30:10.047632460Z","published":"2026-06-24T15:31:48Z","database_specific":{"github_reviewed_at":"2026-09-25T19:18:59Z","nvd_published_at":"2026-06-24T14:17:36Z","cwe_ids":["CWE-862"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57300"},{"type":"WEB","url":"https://github.com/jenkinsci/mcp-server-plugin/commit/ffe5ae770f3bd7e88c99aea3018263af0b2f9cc4"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/mcp-server-plugin"},{"type":"WEB","url":"https://github.com/jenkinsci/mcp-server-plugin/releases/tag/0.178.vffe5a_e770f3b_"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3759"}],"affected":[{"package":{"name":"io.jenkins.plugins:mcp-server","ecosystem":"Maven","purl":"pkg:maven/io.jenkins.plugins/mcp-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.178.vffe5a"}]}],"versions":["0.102.vf677b_eb_da_e4f","0.104.v935c459ca_ee2","0.109.vea_d3ec3083f1","0.116.v335308141e4e","0.119.v479294b_419a_7","0.130.v7837b_2a_5447e","0.138.v7c6a_22ee9160","0.148.v6b_c057f27738","0.149.ve5cd2f59de01","0.158.v8e18e64dd93c","0.16.vc9132432728d","0.166.v6a_0b_15a_7fd59","0.167.v7c50149715fa_","0.168.v13951585050d","0.17.v941ed9da_c023","0.172.174.v9f72da_90a_710","0.172.v9db_cb_43cdb_cc","0.174.v2747878a_eedb_","0.177.v629fdb_2557fe","0.25.v59ca_c2d5ffc5","0.26.v4a_0d810a_7f71","0.27.v4034b_d4c4cb_5","0.33.vecd845512255","0.34.v9f214cb_76168","0.35.v03801a_87ff6d","0.37.v5d2d8c089e8b_","0.41.vdd84b_1430491","0.46.v43ff45cf7fe5","0.57.vc17d46a_5d10b_","0.77.veb_c7b_a_b_f0445","0.84.v50ca_24ef83f2","0.86.v7d3355e6a_a_18","0.88.vde1b_2e64212c","0.89.v1518513fe167","0.90.v46fb_a_0b_0e4a_3","0.92.v575c7c143c44","0.95.vb_c1a_8b_ca_216f"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-mpff-xhg4-vr45/GHSA-mpff-xhg4-vr45.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}