Impact
The Jenkins Script Security Plugin does not verify the method invoked through a proxy when a sandboxed Groovy script coerces a value to an interface. If the coerced value implements a method that has the same name as an interface method, the plugin allows execution of that method. This flaw lets an attacker who can author and run sandboxed scripts escape the sandbox and execute arbitrary code in the Jenkins controller JVM. The weakness is a classic missing security check (CWE‑693), offering a direct path to code execution on the host system.
Affected Systems
Any Jenkins installation running Script Security Plugin version 1415.v9a_f9b_3a_c253d or earlier is vulnerable. The plugin is part of the Jenkins ecosystem and is used to enforce sandbox constraints on Groovy scripts, including those executed within Pipelines. No specific operating system or JDK version constraints are mentioned, so any machine hosting the affected Jenkins instance is at risk.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high‑severity remote code execution vulnerability. An EPSS score of less than 1% suggests exploitation is currently unlikely but the vulnerability remains present. The issue is not listed in the CISA KEV catalog. Attackers require the ability to drop and run sandboxed scripts, a privilege granted to users who author Pipelines or scripts. With such permissions, a crafted script can coerce an object with a malicious method, bypass the sandbox, and run code inside the controller JVM.
OpenCVE Enrichment