CVE-2025-53652
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.
- Published Jul 9, 2025
- CVSS 8.2 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- XWiki CVE-2025-24893 Exploited in the Wild VulnCheck Blog ·
- ICTBroadcast Command Injection Actively Exploited (CVE-2025-2611) VulnCheck Blog ·
- Oracle E-Business Suite CVE-2025-61882 Exploited in Extortion Attacks VulnCheck Blog ·