CVE-2026-57282: Jenkins Git Client
Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.
Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.
Affected products
- Jenkins Git Client: before 6.6.1 (fixed in 6.6.1)
Published 2026-06-24. Last modified 2026-06-26.