Vulnerability GHSA-cfj9-2vgr-hpxp

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 24, 2026 at 03:31 PM UTC
Jenkins Script Security Plugin has a script security bypass vulnerability
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1

Summary

Jenkins Script Security Plugin has a script security bypass vulnerability

Details

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations such as @CompileStatic and @TypeChecked that carry an extensions member, which causes Groovy to load and execute a script from the classpath at compile time, before the sandbox is applied.

This may allow attackers able to define and run sandboxed scripts to execute code outside the sandbox, in the rare case that a suitable Groovy script is present on the classpath of the component that evaluates the script.

The Jenkins security team has been unable to identify any Groovy source files in Jenkins core or plugins that would allow attackers to execute dangerous code. While the severity of this issue is declared as High due to the potential impact, successful exploitation is considered very unlikely.

Script Security Plugin 1402.1405.vc96e74964250 rejects any annotation carrying an extensions member during sandbox compilation, before Groovy can resolve or execute the referenced script.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
3 months ago
Jenkins Script Security Plugin sandbox bypass vulnerability
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-c3jm-9vj7-5v66
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-c3jm-9vj7-5v66
Medium Risk
5 months ago
Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-p334-gfhq-c7w6
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-p334-gfhq-c7w6
Medium Risk
1 year ago
Missing permission check in Jenkins Script Security Plugin
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-jv82-75fh-23r7
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-jv82-75fh-23r7
High Risk
2 years ago
Jenkins Script Security Plugin sandbox bypass vulnerability
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-2g4q-9vm9-9fw4
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-2g4q-9vm9-9fw4
High Risk
2 years ago
Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-v63g-v339-2673
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-v63g-v339-2673
View all vulnerabilities for these packages

Timeline

Published
3 months ago
June 24, 2026 at 03:31 PM UTC
Last Modified
2 days ago
September 25, 2026 at 06:15 PM UTC