Arbitrary Command Injection Vulnerability in Jenkins Git client Plugin
CVE-2025-67640

5MEDIUM

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
10 December 2025

What is CVE-2025-67640?

The Jenkins Git client Plugin version 6.4.0 and earlier contains a vulnerability wherein it fails to properly escape the path to the workspace directory. This issue arises during the generation of a temporary shell script, creating a potential security risk. Attackers with control over the workspace directory name could exploit this flaw to inject arbitrary operating system commands, compromising the integrity of the system.

Affected Version(s)

Jenkins Git client Plugin 0 <= 6.4.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-67640 : Arbitrary Command Injection Vulnerability in Jenkins Git client Plugin