Executive brief
The Jenkins Script Security Plugin is used to safely run user-provided scripts by restricting them to a 'sandbox' that prevents unauthorized actions. A vulnerability in this plugin allows users with permission to run scripts to bypass these safety restrictions and execute unauthorized code on the Jenkins server. While exploitation requires a specific type of script to already be present on the server's file system, a successful attack could lead to full system compromise.
Technical details
The Jenkins Script Security Plugin fails to reject Groovy Abstract Syntax Tree (AST) transformation annotations, such as @CompileStatic or @TypeChecked, when they include an 'extensions' member. This member instructs Groovy to load and execute a script from the classpath during the compilation phase, which occurs before the sandbox protections are applied. An attacker with permissions to define and run sandboxed Groovy scripts can exploit this to achieve code execution outside the sandbox, provided a suitable Groovy script is available on the component's classpath. Although the Jenkins security team has not identified default scripts in core or common plugins that facilitate this, the vulnerability is rated High due to the potential for sandbox escape. The issue is resolved in version 1402.1405.vc96e74964250.
Affected products
- Jenkins Project Script Security Plugin 1402.v94c9ce464861 and earlier
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory
- 2026-06-24: patched