CVE-2025-67640 Details
Description
Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands.
A command injection vulnerability has been identified in the Jenkins Git Client Plugin, affecting versions through 6.4.0. The issue arises because the plugin does not properly escape the workspace directory path when creating temporary shell scripts. This flaw allows attackers who can control the workspace directory name to inject arbitrary operating system commands.
Users should update the Git Client Plugin to version 6.4.1, which addresses the vulnerability by properly escaping the workspace directory path.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2025-12-10/#SECURITY-3614 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins git client | < 6.4.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 17, 2025 | Initial Analysis | [email protected] |
| Dec 10, 2025 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | New CVE Received | [email protected] |