Back

HIGH

jenkins-script-security-plugin: Jenkins Script Security Plugin: Sandbox bypass leading to arbitrary code execution

Published Jun 24, 2026

Description

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.

Affected products

Remediation

Red Hat statement

Red Hat rates this as an Important vulnerability in the Jenkins Script Security Plugin. Attackers with the ability to provide sandboxed Groovy scripts can bypass sandbox protections due to improper handling of implicit type casts in typed for-each loops, allowing arbitrary constructor invocation and potential code execution within the Jenkins JVM. The scope is unchanged (S:U) because the sandbox and the Jenkins controller share the same security authority — a sandbox escape executes code in the same context rather than crossing a trust boundary to a separate system.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner jenkins
Published Jun 24, 2026
Updated Jun 24, 2026
Reserved Jun 24, 2026
CISA Vulnrichment
Updated Jun 24, 2026
NVD
Status Analyzed
Modified Jun 26, 2026
Red Hat
Severity Important
Public date Jun 24, 2026
GHSA-C3JM-9VJ7-5V66