CVE-2026-57282 PUBLISHED

Assigner: jenkins
Reserved: 24.06.2026 Published: 24.06.2026 Updated: 24.06.2026

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.

Product Status

Vendor Jenkins Project
Product Jenkins Git client Plugin
Versions Default: unaffected
  • affected from 0 to 6.6.0 (incl.)

References