GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins Script Security Plugin: @Builder builderStrategy escapes the Groovy sandbox

CVSS 8.5CVE-2026-92126Control plane, storage & DevOpscurated

Impact

The plugin does not reject @Builder annotations whose builderStrategy member names an arbitrary class, so anyone allowed to define and run a sandboxed script - including an ordinary Pipeline - can execute code outside the sandbox, provided a suitable class sits on the classpath of the script-evaluating component. That is code execution as the Jenkins controller process, and CVSS marks a scope change (S:C). For a GPU fleet the Jenkins controller is usually the thing holding registry credentials, kubeconfigs and node SSH keys for the build and model-release pipelines, so a sandbox escape by a developer with only Pipeline-authoring rights turns into control over what images and model artifacts land on the GPU nodes. The sandbox is the entire authorization boundary here: exploitation needs no admin rights, only permission to run a job.

Who can reach it

Any authenticated Jenkins user with permission to define and run sandboxed scripts or Pipelines, reachable over the network wherever the controller UI or SCM-driven pipelines are. Authentication required, but only at low privilege (PR:L); AC:H because a usable class must be on the classpath.

What to do

Upgrade Script Security Plugin past 1415.v9a_f9b_3a_c253d per the Jenkins advisory of 2026-09-16 and restart the controller - a plugin update plus controller restart, which interrupts running builds but touches no GPU nodes. The record does not name the fixed release; take it from the advisory. Until then, restrict who may define and run Pipeline scripts and require admin approval for script changes.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.