MEDIUM

CVE-2026-57282

Jenkins Git Client 2026-06-24 CVSS v3.1
CVSS
5

Description

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.

Summary dbcve.org

The Jenkins Git client Plugin 6.6.0 and earlier fails to properly escape workspace directory names when they are embedded into generated SSH wrapper scripts. An attacker who can control the workspace directory name can inject arbitrary OS commands that will be executed on the Jenkins agent.

Mitigation

Upgrade the Jenkins Git client Plugin to a patched version when available, and restrict or sanitize build workspace directory names to prevent untrusted users from controlling them.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

0.25%
Probability of exploitation in next 30 days
17.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE