Protection mechanism failure in Script Security - CVE-2026-57280
Published: June 29, 2026
Script Security
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the affected plugin does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts. A remote user can invoke arbitrary constructors and bypass the sandbox protection.