CVE-2025-53652: Jenkins Git Parameter
High severity, CVSS 8.2. EPSS: 0.7% chance of exploitation in the next 30 days.
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.
Affected products
- Jenkins Git Parameter: before 444.vca_b_84d3703c2 (fixed in 444.vca_b_84d3703c2)
Published 2025-07-09. Last modified 2026-06-17.