GHSA-c9c2-wcxh-3w5j
GitHub Security Advisory
Sandbox escape in Jenkins Email Extension Plugin
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Affected Packages
Maven
org.jenkins-ci.plugins:email-ext
Affected versions:
0
(fixed in 2.94)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 5, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.