<Vulnerability name="CVE-2026-57281">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-06-24T13:20:04</PublicDate>
    <Bugzilla id="2492200" url="https://bugzilla.redhat.com/show_bug.cgi?id=2492200" xml:lang="en:us">
jenkins-script-security-plugin: Jenkins Script Security Plugin: Arbitrary code execution outside sandbox
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>8.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-917</CWE>
    <Details xml:lang="en:us" source="Mitre">
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the Jenkins Script Security Plugin. Attackers with the ability to run sandboxed Groovy scripts can exploit this vulnerability to execute arbitrary code outside the sandbox environment. This is due to the plugin's failure to reject Groovy Abstract Syntax Tree (AST) transformation annotations that include an extensions member, allowing unauthorized script execution if a suitable script exists on the classpath.
    </Details>
    <Statement xml:lang="en:us">
This flaw has an Important impact as the Jenkins Script Security Plugin shipped in Red Hat OpenShift Container Platform is susceptible to a sandbox bypass. An authenticated attacker with the ability to run sandboxed Groovy scripts can exploit improperly handled AST transformation annotations to execute arbitrary code outside the sandbox on the Jenkins controller. Exploitation requires a suitable script to be present on the classpath, increasing attack complexity.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:ocp_tools">
        <ProductName>OpenShift Developer Tools and Services</ProductName>
        <FixState>Affected</FixState>
        <PackageName>jenkins</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ocp_tools">
        <ProductName>OpenShift Developer Tools and Services</ProductName>
        <FixState>Affected</FixState>
        <PackageName>jenkins-2-plugins</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ocp_tools">
        <ProductName>OpenShift Developer Tools and Services</ProductName>
        <FixState>Affected</FixState>
        <PackageName>ocp-tools-4/jenkins-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ocp_tools">
        <ProductName>OpenShift Developer Tools and Services</ProductName>
        <FixState>Affected</FixState>
        <PackageName>ocp-tools-4/jenkins-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-57281
https://nvd.nist.gov/vuln/detail/CVE-2026-57281
https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3793
    </References>
</Vulnerability>