GHSA-cfj9-2vgr-hpxp

Suggest an improvement
Source
https://github.com/advisories/GHSA-cfj9-2vgr-hpxp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-cfj9-2vgr-hpxp/GHSA-cfj9-2vgr-hpxp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cfj9-2vgr-hpxp
Aliases
Published
2026-06-24T15:31:47Z
Modified
2026-09-25T18:15:04Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Jenkins Script Security Plugin has a script security bypass vulnerability
Details

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations such as @CompileStatic and @TypeChecked that carry an extensions member, which causes Groovy to load and execute a script from the classpath at compile time, before the sandbox is applied.

This may allow attackers able to define and run sandboxed scripts to execute code outside the sandbox, in the rare case that a suitable Groovy script is present on the classpath of the component that evaluates the script.

The Jenkins security team has been unable to identify any Groovy source files in Jenkins core or plugins that would allow attackers to execute dangerous code. While the severity of this issue is declared as High due to the potential impact, successful exploitation is considered very unlikely.

Script Security Plugin 1402.1405.vc96e74964250 rejects any annotation carrying an extensions member during sandbox compilation, before Groovy can resolve or execute the referenced script.

Database specific
{
    "cwe_ids":  [
        "CWE-917",
        "CWE-93"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-25T18:06:00Z",
    "nvd_published_at":  "2026-06-24T14:17:34Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:script-security

Package

Name
org.jenkins-ci.plugins:script-security
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/script-security

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1402.1405.vc96e74964250

Affected versions

1.*
1.0-beta-1
1.0-beta-2
1.0-beta-3
1.0-beta-4
1.0-beta-5
1.0-beta-6
1.0
1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8
1.9
1.10
1.11
1.12
1.13
1.14
1.15
1.16
1.17
1.18
1.18.1
1.19
1.20
1.21
1.22
1.23
1.24
1.25
1.26
1.27
1.28
1.29
1.29.1
1.30
1.31
1.33
1.34
1.35
1.36
1.37
1.38
1.39
1.40
1.41
1.42
1.43
1.44
1.44.1
1.45
1.46
1.46.1
1.47
1.48
1.49
1.50
1.51
1.52
1.53
1.54
1.54.1
1.54.2
1.54.3
1.54.4
1.55
1.56
1.57
1.57.1
1.57.2
1.57.3
1.57.4
1.57.5
1.57.6
1.58
1.59
1.60
1.60.1
1.61
1.62
1.63
1.63.1
1.64
1.65
1.66
1.66.1
1.66.2
1.66.3
1.66.4
1.66.5
1.67
1.68
1.69
1.70
1.71
1.72
1.73
1.74
1.75
1.76
1.77
1.78
1.78.1
1118.*
1118.vba21ca2e3286
1125.*
1125.v132f99385e1b_
1131.*
1131.v8b_b_5eda_c328e
1138.*
1138.v8e727069a_025
1140.*
1140.vf967fb_efa_55a_
1145.*
1145.vb_cf6cf6ed960
1145.1148.vf6d17a_a_a_eef6
1146.*
1146.vdf547f19a_473
1158.*
1158.v7c1b_73a_69a_08
1172.*
1172.v35f6a_0b_8207e
1175.*
1175.v4b_d517d6db_f0
1175.1177.vda_175b_77d144
1175.1179.vea_f7532629e1
1175.1180.v36a_3fb_2dec9c
1183.*
1183.v774b_0b_0a_a_451
1184.*
1184.v85d16b_d851b_3
1189.*
1189.vb_a_b_7c8fd5fde
1190.*
1190.v65867a_a_47126
1209.*
1209.v50b_005db_19db
1218.*
1218.v39ca_7f7ed0a_c
1228.*
1228.vd93135a_2fb_25
1229.*
1229.v4880b_b_e905a_6
1244.*
1244.ve463715a_f89c
1251.*
1251.vfe552ed55f8d
1251.1253.v4e638b_e3b_221
1264.*
1264.vecf66020eb_7d
1265.*
1265.va_fb_290b_4b_d34
1269.*
1269.v639888f5e366
1271.*
1271.vdede89739a_81
1273.*
1273.v66c1964f0dfd
1274.*
1274.v2b_33362a_f2f5
1275.*
1275.v23895f409fb_d
1281.*
1281.v22fb_899df1a_e
1294.*
1294.v99333c047434
1301.*
1301.v0079b_cd0cdfa_
1305.*
1305.v487433146192
1310.*
1310.vf24a_dfce068b_
1313.*
1313.v7a_6067dc7087
1321.*
1321.va_73c0795b_923
1326.*
1326.vdb_c154de8669
1335.*
1335.vf07d9ce377a_e
1336.*
1336.vf33a_a_9863911
1341.*
1341.va_2819b_414686
1354.*
1354.va_70a_fe478c7f
1358.*
1358.vb_26663c13537
1361.*
1361.v913100720139
1362.*
1362.v67dc1f0e1b_b_3
1362.1364.v4cf2dc5d8776
1365.*
1365.v4778ca_84b_de5
1365.1367.va_3b_b_89f8a_95b_
1366.*
1366.vd44b_49a_5c85c
1367.*
1367.vdf2fc45f229c
1368.*
1368.vb_b_402e3547e7
1369.*
1369.v9b_98a_4e95b_2d
1373.*
1373.vb_b_4a_a_c26fa_00
1378.*
1378.vf25626395f49
1385.*
1385.v7d2d9ec4d909
1399.*
1399.ve6a_66547f6e1
1402.*
1402.v94c9ce464861

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-cfj9-2vgr-hpxp/GHSA-cfj9-2vgr-hpxp.json"