Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-67640


Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands.


Published

2025-12-10T17:15:56.517

Last Modified

2025-12-17T17:31:23.030

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.0 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins git_client < 6.4.1 Yes

References