Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
CVE-2025-64132
CVE-2025-64132
Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.
Published Oct 30, 2025
https://github.com/advisories/GHSA-mrpq-9jr3-rqq9
CVSS Score
Medium
5.3
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
maven
io.jenkins.plugins/mcp-server
0.16.vc9132432728d
maven
io.jenkins.plugins/mcp-server
0.17.v941ed9da_c023
maven
io.jenkins.plugins/mcp-server
0.25.v59ca_c2d5ffc5
maven
io.jenkins.plugins/mcp-server
0.26.v4a_0d810a_7f71
maven
io.jenkins.plugins/mcp-server
0.27.v4034b_d4c4cb_5
maven
io.jenkins.plugins/mcp-server
0.33.vecd845512255
maven
io.jenkins.plugins/mcp-server
0.34.v9f214cb_76168
maven
io.jenkins.plugins/mcp-server
0.35.v03801a_87ff6d
maven
io.jenkins.plugins/mcp-server
0.37.v5d2d8c089e8b_
maven
io.jenkins.plugins/mcp-server
0.41.vdd84b_1430491
maven
io.jenkins.plugins/mcp-server
0.46.v43ff45cf7fe5
maven
io.jenkins.plugins/mcp-server
0.57.vc17d46a_5d10b_
maven
io.jenkins.plugins/mcp-server
0.77.veb_c7b_a_b_f0445
maven
io.jenkins.plugins/mcp-server
0.84.v50ca_24ef83f2
1-14 of 14
CVE-2025-64132 | Components Impacted | Sonatype Guide | Sonatype Guide