← Vulnerability feed

Vulnerability record · CVE-2019-10431 · published 1 October 2019

CVE-2019-10431: Jenkins script security code injection vulnerability

Jenkins · Script Security

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.

9.9 CVSS 3.1 Critical EPSS 2.7% · top 14.7% CWE-94 · Code injection
9.9CVSS 3.1 base score, v2 6.5
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-10431 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2019-1003029Jenkins Script Security Plugin sandbox bypass allows code executionThe Jenkins Script Security Plugin 1.53 and earlier fails to properly enforce its Groovy sandbox in GroovySandbox.java and SecureGroovyScript.java, l…KEVEPSS 74%analysed9.9CVE-2022-43401Jenkins script security vulnerabilityA sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Script Security Plugin 1183.v77…EPSS 1.3%9.9CVE-2022-43403Jenkins script security vulnerabilityA sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and ea…EPSS 1.6%9.9CVE-2022-43404Jenkins script security vulnerabilityA sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructors in Jenkins Script Security …EPSS 1.2%9.9CVE-2020-2279Jenkins script security vulnerabilityA sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to pro…EPSS 2.1%9.8CVE-2024-34144Jenkins Script Security Plugin sandbox bypass via crafted constructorsJenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier fails to properly restrict crafted constructor bodies, allowing a sandbox bypass. An a…EPSS 48%analysed9.8CVE-2019-1003040Jenkins script security vulnerabilityA sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scri…EPSS 3.4%8.8CVE-2026-92122Jenkins script security vulnerabilityJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script c…EPSS 0.63%

Source: NIST National Vulnerability Database (record CVE-2019-10431), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.