Skip to main content
Vulnerability Database/CVE-2025-67640

CVE-2025-67640: Jenkins Git Client RCE Vulnerability

CVE-2025-67640 is a remote code execution flaw in Jenkins Git Client Plugin that allows attackers to inject arbitrary OS commands through workspace directory names. This article covers technical details, affected versions, and mitigation steps.

Published:

CVE-2025-67640 Overview

CVE-2025-67640 is an OS command injection vulnerability in the Jenkins Git client Plugin versions 6.4.0 and earlier. The plugin generates a temporary shell script that includes the workspace directory path as an argument. It fails to correctly escape that path, allowing attackers who control the workspace directory name to inject arbitrary operating system commands. The flaw is tracked under [CWE-78] (Improper Neutralization of Special Elements used in an OS Command).

Critical Impact

Attackers with permission to influence the workspace directory name can execute arbitrary OS commands on the Jenkins agent or controller running the affected Git client Plugin.

Affected Products

  • Jenkins Git client Plugin 6.4.0
  • Jenkins Git client Plugin versions earlier than 6.4.0
  • Jenkins deployments using the jenkins:git_client component

Discovery Timeline

Technical Details for CVE-2025-67640

Vulnerability Analysis

The Jenkins Git client Plugin creates a temporary shell script during Git operations. That script embeds the path to the job workspace directory as a command argument. The plugin does not properly escape shell metacharacters within the path before writing the script. When the script executes, the shell parses injected metacharacters as commands rather than as part of the workspace path.

Exploitation requires an attacker to control the workspace directory name. In Jenkins, users with permission to configure jobs can influence the custom workspace path. That configuration surface is the primary entry point for the injection. Successful exploitation runs commands with the privileges of the Jenkins agent process executing the Git operation.

The vulnerability is classified under [CWE-78]. The EPSS model estimates a low near-term exploitation probability. No public proof-of-concept exploit is currently listed in the enriched data.

Root Cause

The root cause is missing shell argument escaping. The plugin concatenates the workspace directory path into a generated shell script without applying quoting or metacharacter neutralization. Characters such as ;, `, $(), &&, and | are interpreted by the shell rather than treated as literal path components.

Attack Vector

The attack vector is network-adjacent through the Jenkins web interface. An authenticated user with Job/Configure or equivalent permission sets a custom workspace directory containing shell metacharacters. When a build runs and the Git client Plugin generates its temporary script, the injected payload executes on the agent. Refer to Jenkins Security Advisory 2025-12-10 for authoritative technical detail.

// No verified proof-of-concept code is published for CVE-2025-67640.
// The vulnerability arises from unescaped workspace paths embedded in a
// shell script generated by the Git client Plugin. See the Jenkins advisory
// linked above for authoritative details.

Detection Methods for CVE-2025-67640

Indicators of Compromise

  • Jenkins job configurations that define custom workspace paths containing shell metacharacters such as ;, |, &, `, or $()
  • Unexpected child processes spawned by the Jenkins agent process during Git checkout or fetch operations
  • Temporary shell scripts under the Jenkins agent working directory that include unusual command sequences alongside Git commands

Detection Strategies

  • Audit all job configurations for non-standard customWorkspace values and flag entries containing shell metacharacters
  • Enable Jenkins audit logging for job configuration changes and review modifications made by non-administrative users
  • Correlate Git plugin activity with process execution telemetry from agents to identify unexpected shell command chains

Monitoring Recommendations

  • Monitor the Jenkins agent process tree for shell invocations that do not correspond to expected build steps
  • Track installed plugin versions across the Jenkins fleet and alert when git-client remains at 6.4.0 or earlier
  • Ingest Jenkins system and audit logs into a centralized logging platform for retention and correlation with endpoint telemetry

How to Mitigate CVE-2025-67640

Immediate Actions Required

  • Upgrade the Jenkins Git client Plugin to a version later than 6.4.0 as identified in Jenkins Security Advisory 2025-12-10
  • Restrict Job/Configure and Job/Create permissions to trusted users only
  • Review existing jobs for suspicious custom workspace paths and remediate any injected content

Patch Information

Jenkins published SECURITY-3614 in the Jenkins Security Advisory 2025-12-10. Administrators should update the Git client Plugin through the Jenkins plugin manager to the fixed release referenced in that advisory. Restart Jenkins after upgrading to ensure the patched plugin is loaded on the controller and all connected agents.

Workarounds

  • Remove or disable the Git client Plugin on controllers where an immediate upgrade is not possible
  • Enforce the principle of least privilege by limiting job configuration rights and disabling anonymous or authenticated read-write access
  • Use folder-level authorization to constrain which users can define custom workspace paths on sensitive jobs
bash
# Check the installed Git client Plugin version via the Jenkins CLI
java -jar jenkins-cli.jar -s https://jenkins.example.com/ list-plugins | grep git-client

# Upgrade using the Jenkins plugin manager UI or the CLI
java -jar jenkins-cli.jar -s https://jenkins.example.com/ install-plugin git-client -deploy

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.