Jenkins Git client Plugin has an OS command injection vulnerability on agents in Git client Plugin
Moderate severity GitHub Reviewed Published Dec 10, 2025 to the GitHub Advisory Database • Updated Dec 10, 2025
Description
Published by the National Vulnerability DatabaseDec 10, 2025
Published to the GitHub Advisory Database Dec 10, 2025
Last updated Dec 10, 2025
Reviewed Dec 10, 2025
Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands.
References