Intel

AIKIDO-2026-327524

pipeline-groovy-lib is vulnerable to Cross-Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF)CVE-2026-84663 Published Today

43

Medium Risk

This Affects:

JAVApipeline-groovy-lib
0.0.1 - 798
Fixed in 805
Are you affected? Scan for Free

TL;DR

An HTTP endpoint in Pipeline: Groovy Libraries Plugin does not require POST requests. Attackers can trigger cache deletion actions through cross-site request forgery against users with required permissions. The fix enforces POST for the affected endpoint.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users with permission to manage Pipeline shared library caches browse other sites while signed in to Jenkins.

Background info

pipeline-groovy-lib is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.1 - 798.

How to fix this

Upgrade the io.jenkins.plugins:pipeline-groovy-lib library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform