CVE-2025-5806: Jenkins Gatling Plugin Vulnerable to Cross-Site Scripting (XSS)
(updated )
Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.
References
- github.com/advisories/GHSA-gw97-cqwg-xmh4
- github.com/jenkinsci/gatling-plugin
- github.com/jenkinsci/gatling-plugin/commit/141bd3a811ab641bf618ec588b615cf87469b222
- github.com/jenkinsci/gatling-plugin/pull/27
- github.com/jenkinsci/gatling-plugin/releases/tag/136.vb_9009b_3d33a_e
- nvd.nist.gov/vuln/detail/CVE-2025-5806
- www.jenkins.io/security/advisory/2025-06-06/
Code Behaviors & Features
Detect and mitigate CVE-2025-5806 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →