The block comes from the core path-traversal guard in FilePath operations. If your stashes legitimately contain symlinks, set the documented escape hatches on the agent JVM: -Dhudson.FilePath.ALLOW_REENTRY_PATH_TRAVERSAL=true and -Dhudson.FilePath.ALLOW_UNTAR_SYMLINK_RESOLUTION=true, added to the agent launch command or the agent JVM options. Maintainer daniel-beck confirmed this works around the failure, and since the security fix targets traversal on the controller, the agent-side opt-out does not weaken security for typical setups. Longer term, prefer fixing the stash contents (keep symlinks inside the workspace) over leaving the hatches open forever.

Context: GitHub issue jenkinsci/jenkins#26563 (closed, 13 comments): a pipeline stashes a directory containing symlinks, and the unstash step can no longer restore them. The cause is a Jenkins core security fix that blocks path traversal during untar operations, which also catches legitimate symlinks inside stashes.