PatchSiren cyber security CVE debrief
CVE-2019-1003000 Jenkins project CVE debrief
CVE-2019-1003000 describes a sandbox bypass in Jenkins Script Security Plugin 1.49 and earlier. If an attacker can provide sandboxed scripts, the flaw may let them escape the intended restrictions and execute arbitrary code on the Jenkins master JVM. Because the controller/master is central to Jenkins operations, this is a high-impact issue for environments that accept or process untrusted Groovy scripts.
- Vendor
- Jenkins project
- Product
- Script Security Plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2019-01-22
- Original CVE updated
- 2026-06-14
- Advisory published
- 2026-06-14
- Advisory updated
- 2026-06-14
Who should care
Jenkins administrators, platform owners, and security teams running Script Security Plugin 1.49 or earlier, especially in installations where users, jobs, or integrations can submit sandboxed scripts.
Technical summary
The vulnerability is identified in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java in Script Security Plugin 1.49 and earlier. The issue is a sandbox bypass: attackers with the ability to provide sandboxed scripts may be able to execute arbitrary code on the Jenkins master JVM instead of remaining confined to the sandbox.
Defensive priority
High. Treat as urgent in any Jenkins environment that accepts user-supplied or integration-supplied sandboxed scripts, because successful exploitation can result in arbitrary code execution on the Jenkins master JVM. The supplied EPSS signal is very high (0.94443; 99.992 percentile), which further increases priority for exposure review and remediation.
Recommended defensive actions
- Upgrade Jenkins Script Security Plugin to a version that remediates this sandbox bypass.
- Review where sandboxed scripts are accepted and restrict script submission to trusted users and workflows.
- Treat the Jenkins master/controller as highly sensitive and limit network and administrative access to it.
- Audit Jenkins jobs, shared libraries, and integrations that rely on Groovy sandbox execution.
- Monitor for unexpected script execution, configuration changes, or other signs of controller compromise.
Evidence notes
The supplied CVE description states that Script Security Plugin 1.49 and earlier contains a sandbox bypass in GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM. The supplied FIRST EPSS snapshot for 2026-05-15 reports an EPSS score of 0.94443 and percentile 0.99992 for CVE-2019-1003000. No CVSS score was supplied in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-1003000 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-1003000
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-1003000 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1003000
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.first.org/epss/
first_epss
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.