{"id":"CVE-2026-55060","published":"2026-09-21T15:17:29.277","lastModified":"2026-09-21T21:17:05.213","description":"GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames, remote material URLs, and internal material paths for materials the user cannot otherwise access. Exploitation depends on unpredictable process timing, and credentials, environment variables, and user-defined secrets remain masked or omitted. This issue is fixed in version 26.1.0.","cvssScore":3.7,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://github.com/gocd/gocd/commit/fbf832f9358d96466bb87fad11a1de0ba935fea8","tags":[]},{"url":"https://github.com/gocd/gocd/releases/tag/26.1.0","tags":[]},{"url":"https://github.com/gocd/gocd/security/advisories/GHSA-vqjf-7pf8-hgwr","tags":[]},{"url":"https://www.gocd.org/releases/#26-1-0","tags":[]}],"exploitRefs":[{"url":"https://github.com/gocd/gocd/commit/fbf832f9358d96466bb87fad11a1de0ba935fea8","tags":[]},{"url":"https://github.com/gocd/gocd/releases/tag/26.1.0","tags":[]},{"url":"https://github.com/gocd/gocd/security/advisories/GHSA-vqjf-7pf8-hgwr","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an authenticated internal user to view sensitive information from source control child processes, including command-line arguments and material paths, which could be exploited for unauthorized access.","exploitability":"Exploitation is moderately difficult due to timing dependencies but requires the attacker to have valid credentials and knowledge of running processes.","blast_radius":"If exploited, the impact is limited to viewing masked or omitted sensitive information, potentially leading to data exposure or misconfiguration issues.","remediation":"Upgrade to GoCD version 26.1.0 immediately to address the authorization vulnerability.","tags":["auth-bypass","info-leak","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:36:24.829Z"}}