pinned plugin cache poisoning in nextflow
ghsa-654x-pf35-q3v4 let a lower-trust local user pre-populate a shared plugin cache with attacker-controlled pf4j plugin code, which a victim workflow later loads and executes as the victim user
August 18, 2026 5 min read vulnerability cve local cache poisoning code execution