Intel

AIKIDO-2026-500513

file-parameters is vulnerable to Path Traversal

Path TraversalCVE-2026-84671 Published Today

88

High Risk

This Affects:

JAVAfile-parameters
0.0.1 - 425
Fixed in 433
Are you affected? Scan for Free

TL;DR

A @DataBoundConstructor path in File Parameter Plugin stores uploaded files using a parameter name as a path without applying the existing safety validation. Attackers able to submit certain forms can write files to arbitrary controller filesystem locations, including paths that can lead to code execution. The fix applies the same parameter name validation in that constructor.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users can submit forms that bind File Parameter plugin definitions.

Background info

file-parameters is vulnerable to Path Traversal in versions 0.0.1 - 425.

How to fix this

Upgrade the io.jenkins.plugins:file-parameters library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform