CVE-2026-57281: CRLF Injection
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57281?
CVE-2026-57281 has a high severity rating of 7.5 based on the CVSS 3.1 scoring system.
How do I fix CVE-2026-57281?
To fix CVE-2026-57281, upgrade to Jenkins Script Security Plugin version 1402.v94c9ce464861 or later.
What systems are affected by CVE-2026-57281?
CVE-2026-57281 affects Jenkins Script Security Plugin version 1402.v94c9ce464861 and earlier.
What type of vulnerability is CVE-2026-57281?
CVE-2026-57281 is classified as a CRLF Injection vulnerability.
What impact does CVE-2026-57281 have on Jenkins users?
CVE-2026-57281 allows attackers to execute code outside the sandbox when running sandboxed Groovy scripts.