cbcvebase.
CVE-2025-67640
published 2025-12-10

CVE-2025-67640: Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell…

PriorityP431medium5CVSS 3.1
AVNACHPRLUINSUCLILAL
EPSS
0.21%
10.5th percentile
Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands.

Affected

10 ranges
VendorProductVersion rangeFixed in
jenkinsblazemeter_plugin——
jenkinscoverage_plugin——
jenkinsgit_client< 6.4.16.4.1
jenkinsgit_client_plugin——
jenkinshashicorp_vault_plugin——
jenkinsjenkins_core——
jenkinsjenkins_lts——
jenkinsjenkins_weekly——
jenkinsredpen_pipeline_reporter_for_jira_plugin——
jenkins_projectjenkins_git_client_plugin<= 6.4.0—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.