cbcvebase.
CVE-2025-64132
published 2025-10-29

CVE-2025-64132: Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and…

PriorityP431medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.24%
14.8th percentile
Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.

Affected

16 ranges
VendorProductVersion rangeFixed in
jenkinsazure_cli_plugin
jenkinsbyteguard_build_actions_plugin
jenkinscurseforge_publisher_plugin
jenkinseggplant_runner_plugin
jenkinsextensible_choice_parameter_plugin
jenkinsjdepend_maven_plugin
jenkinsjdepend_plugin
jenkinsmcp_server< 0.86.v7d3355e6a_a_180.86.v7d3355e6a_a_18
jenkinsmcp_server_plugin
jenkinsnexus_task_runner_plugin
jenkinsopenshift_pipeline_plugin
jenkinspublish_to_bitbucket_plugin
jenkinssaml_plugin
jenkinsstart_windocks_containers_plugin
jenkinsthemis_plugin
jenkins_projectjenkins_mcp_server_plugin<= 0.84.v50ca_24ef83f2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.