cbcvebase.
CVE-2026-57282
published 2026-06-24

CVE-2026-57282: Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script…

PriorityP433medium5CVSS 3.1
AVNACHPRLUINSUCLILAL
EPSS
0.25%
17.1th percentile
Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsactive_directory——
jenkinsactive_directory_plugin——
jenkinsassembla——
jenkinsassembla_plugin——
jenkinsbitbucket_push_and_pull_request——
jenkinsbitbucket_push_and_pull_request_plugin——
jenkinscontrast_continuous_application_security——
jenkinscontrast_continuous_application_security_plugin——
jenkinsec2_fleet——
jenkinsec2_fleet_plugin——
jenkinsexternal_workspace_manager——
jenkinsexternal_workspace_manager_plugin——
jenkinsfitnesse——
jenkinsfitnesse_plugin——
jenkinsgit_client< 6.6.16.6.1
jenkinsgit_client——
jenkinsgit_client_plugin——
jenkinsgit_parameter——
jenkinsgit_parameter_plugin——
jenkinsgitee——
jenkinsgitee_plugin——
jenkinsgithub_branch_source——
jenkinsgithub_branch_source_plugin——
jenkinsgroovy——
jenkinsgroovy_plugin——
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.