Vulnerability Report

CVE-2025-53652

Title: Jenkins Git Parameter Improper Input Validation

Input Validation Error

Proof Of Concept

PoC Available for CVE-2025-53652

CWE Category CWE-20
Published Date Jul 09, 2025
Modified Date Nov 04, 2025
Exploit Status Available
Score 8.2 CVSS v3.1
Exploit Probability (EPSS)
0.07%

Vulnerability Summary

CVE-2025-53652: Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.

CVSS v3.1
Source Entity 134c704f-9b21-4f2e-91b3-4a467353bcc0
Severity HIGH
8.2
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2025-53652 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/pl4tyz/CVE-2025-53652-Jenkins-Git-Parameter-Analysis
View Code
MODIFIED

Vulnerability data or affected products updated.

MODIFIED

Vulnerability data updated via NVD.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector NETWORK
Complexity LOW
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected Stack

No specific products linked.