MEDIUM 5.0 Maven
Jenkins Git client Plugin has an OS command injection vulnerability on agents in Git client Plugin
GHSA-v8hg-m323-jvjq · CVE-2025-67640
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands.
Ready to move
Start Securing
Free, no credit card | First findings in minutes