Jenkins script security plugin
This hub aggregates every CVE we track for Jenkins script security plugin, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
39
CVEs tracked
8
Critical
21
High
1
In CISA KEV
Severity distribution
HIGH21MEDIUM10CRITICAL8
Monthly trend
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
2
0
0
10
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Jenkins script security plugin.
- CVE-2026-92129Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission t...7.5
- CVE-2026-92127Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item...8.0
- CVE-2026-92128Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from th...7.5
- CVE-2026-92126Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to de...8.5
- CVE-2026-92125Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts...8.8
- CVE-2026-92124Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type...8.8
- CVE-2026-92123Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allo...8.8
- CVE-2026-92122Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inh...8.8
- CVE-2026-84659Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, all...4.3
- CVE-2026-84658Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to subm...4.3
- CVE-2026-57280Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attack...8.8
- CVE-2026-57281Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy sc...7.5
- CVE-2026-42519A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.4.3
- CVE-2024-52549Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form val...4.3
- CVE-2024-34145A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers ...8.8
Product normalization is registry-driven with AI assist and human review. How it works