PT-2026-45497 · Hekmon8 · Jenkins-Server-Mcp

Ccccccctfi

·

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-10276

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of the file src/index.ts of the component get build status/get build log/trigger build. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-10276

Affected Products

Jenkins-Server-Mcp