Executive brief
The Jenkins TICS Plugin, used by development teams to integrate code quality analysis into build pipelines, contains an OS command injection vulnerability. An attacker who can control build environment variables can execute arbitrary commands on the build agent, potentially compromising the integrity of builds, accessing sensitive data stored on build servers, or using the compromised agent as a foothold for further attacks on the CI/CD infrastructure.
Technical details
This is an OS command injection vulnerability in Jenkins TICS Plugin version 2025.1.1 and earlier, where build environment variable values are not properly sanitized before being used in shell command construction. The vulnerability is exploitable by attackers able to control or influence build environment variables, which may be possible in multi-tenant build environments or where build parameters are derived from untrusted sources. By injecting shell metacharacters or command separators into environment variable values, an attacker can break out of the intended command and execute arbitrary OS commands with the privileges of the Jenkins agent process. Patch availability should be verified through the Jenkins security advisory and the plugin's update mechanism.
Affected products
- Jenkins TICS Plugin 2025.1.1 and earlier
Timeline
- 2026-09-02: disclosed: Published in Jenkins Security Advisory 2026-09-02
- 2026-09-02: advisory