CVE-2025-67640
MEDIUMJenkins Git Client < 6.4.1 - OS Command Injection
Title source: ruleDescription
Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands.
Scores
CVSS v3
5.0
EPSS
0.0010
EPSS Percentile
27.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-78
Status
published
Affected Products (2)
jenkins/git_client
< 6.4.1
org.jenkins-ci.plugins/git-client
< 6.4.1Maven
Timeline
Published
Dec 10, 2025
Tracked Since
Feb 18, 2026