VYPR
Medium severity5.0NVD Advisory· Published Jun 24, 2026· Updated Jun 26, 2026

CVE-2026-57282

CVE-2026-57282

Description

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

2