Executive brief
hekmon8 Jenkins-server-mcp is a tool that allows AI assistants to interact with Jenkins CI/CD servers to check build statuses and trigger jobs. A security vulnerability in this tool allows an attacker to trick the server into making unauthorized requests to internal or external network locations. This could lead to the exposure of sensitive internal data or unauthorized actions on other private services within the corporate network.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in hekmon8 Jenkins-server-mcp 0.1.0 within the jobPath function of src/index.ts. The application fails to properly validate the 'jobPath' argument before concatenating it into an Axios request URL. By providing a jobPath starting with a leading slash (e.g., '/127.0.0.1:7777/'), an attacker can create a protocol-relative URL that redirects the request to an arbitrary internal or external host instead of the intended Jenkins server. This affects the get_build_status, get_build_log, and trigger_build components. Exploitation requires the ability to invoke these MCP tools, typically requiring low-level authentication. As of the advisory date, no patch has been released by the maintainer.
Affected products
- hekmon8 Jenkins-server-mcp 0.1.0
Timeline
- 2026-04-20: other: Vulnerability discovered by researcher
- 2026-05-11: disclosed: Issue reported on GitHub repository
- 2026-06-01: advisory: CVE published and NVD record created