High severity8.0NVD Advisory· Published Jun 6, 2025· Updated Jun 17, 2026
CVE-2025-5806
CVE-2025-5806
Description
Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- ghsa-coords
- Range: 136.vb_9009b_3d33a_e
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-gw97-cqwg-xmh4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-5806ghsaADVISORY
- www.jenkins.io/security/advisory/2025-06-06/nvdVendor AdvisoryWEB
- www.openwall.com/lists/oss-security/2025/06/06/8nvdMailing ListWEB
- github.com/jenkinsci/gatling-plugin/commit/141bd3a811ab641bf618ec588b615cf87469b222ghsaWEB
- github.com/jenkinsci/gatling-plugin/pull/27ghsaWEB
- github.com/jenkinsci/gatling-plugin/releases/tag/136.vb_9009b_3d33a_eghsaWEB
News mentions
1- Jenkins Security Advisory 2025-06-06Jenkins Security Advisories · Jun 6, 2025