A critical XSS vulnerability (CVE-2025-5806) in Jenkins Gatling Plugin version 136.vb_9009b_3d33a_e allows attackers to bypass Content-Security-Policy protections, enabling arbitrary script execution. Attackers can exploit this by manipulating report content. Currently, there are no patches available; downgrading to version 1.3.0 is advised. Organizations should assess their Jenkins environments and enhance security monitoring.

The npm Threat Landscape: Attack Surface and Mitigations – Unit 42
The npm Threat Landscape: Attack Surface and Mitigations Unit 42


