cbcvebase.
CVE-2025-67640
published 2025-12-10

CVE-2025-67640: Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell…

PriorityP431medium5CVSS 3.1
AVNACHPRLUINSUCLILAL
EPSS
0.19%
8.4th percentile
Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands.

Affected

10 ranges
VendorProductVersion rangeFixed in
jenkinsblazemeter_plugin
jenkinscoverage_plugin
jenkinsgit_client< 6.4.16.4.1
jenkinsgit_client_plugin
jenkinshashicorp_vault_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinsredpen_pipeline_reporter_for_jira_plugin
jenkins_projectjenkins_git_client_plugin<= 6.4.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.