Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.

Published 27 Aug 2026Updated 27 Aug 202649 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.

Affected versions

Jenkins Command Line Interface (CLI): See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 51993Jenkins 2.441 - Local File InclusionMatisse Beckandt2024-04-15VerifiedPoC-in-GitHub · jenkinsci-cert/SECURITY-3314-3315Workaround for disabling the CLI to mitigate SECURITY-3314/CVE-2024-23897 and SECURITY-3315/CVE-2024-23898★ 7jenkinsci-cert2024-01-23CandidatePoC-in-GitHub · binganao/CVE-2024-23897★ 99binganao2024-01-26CandidatePoC-in-GitHub · h4x0r-dz/CVE-2024-23897CVE-2024-23897★ 208h4x0r-dz2024-01-26CandidatePoC-in-GitHub · xaitax/CVE-2024-23897CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner.★ 80xaitax2024-01-26CandidatePoC-in-GitHub · vmtyan/poc-cve-2024-23897★ 2vmtyan2024-01-26CandidatePoC-in-GitHub · yoryio/CVE-2024-23897Scanner for CVE-2024-23897 - Jenkins★ 5yoryio2024-01-27CandidatePoC-in-GitHub · P4x1s/CVE-2024-23897CVE-2024-23897 jenkins-cli★ 15P4x1s2024-01-27CandidatePoC-in-GitHub · 10T4/PoC-Fix-jenkins-rce_CVE-2024-23897on this git you can find all information on the CVE-2024-23897★ 410T42024-01-27CandidatePoC-in-GitHub · wjlin0/CVE-2024-23897CVE-2024-23897 - Jenkins 任意文件读取 利用工具★ 86wjlin02024-01-27CandidatePoC-in-GitHub · Vozec/CVE-2024-23897This repository presents a proof-of-concept of CVE-2024-23897★ 17Vozec2024-01-28CandidatePoC-in-GitHub · r0xDB/CVE-2024-23897Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.★ 0r0xDB2024-01-28CandidatePoC-in-GitHub · viszsec/CVE-2024-23897Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE★ 5viszsec2024-01-29CandidatePoC-in-GitHub · jopraveen/CVE-2024-23897★ 1jopraveen2024-01-29CandidatePoC-in-GitHub · AbraXa5/Jenkins-CVE-2024-23897PoC for Jenkins CVE-2024-23897★ 1AbraXa52024-02-01CandidatePoC-in-GitHub · WLXQqwer/Jenkins-CVE-2024-23897-★ 0WLXQqwer2024-02-04CandidatePoC-in-GitHub · kaanatmacaa/CVE-2024-23897Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability)★ 22kaanatmacaa2024-02-04CandidatePoC-in-GitHub · GraySignal/CVE-2024-23897-Jenkins-Arbitrary-Read-File-VulnerabilityJenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.★ 3GraySignal2024-02-07CandidatePoC-in-GitHub · B4CK4TT4CK/CVE-2024-23897CVE-2024-23897★ 0B4CK4TT4CK2024-02-13CandidatePoC-in-GitHub · godylockz/CVE-2024-23897POC for CVE-2024-23897 Jenkins File-Read★ 44godylockz2024-02-16CandidatePoC-in-GitHub · ifconfig-me/CVE-2024-23897Jenkins Arbitrary File Leak Vulnerability [CVE-2024-23897]★ 0ifconfig-me2024-02-16CandidatePoC-in-GitHub · Ap0dexMe0/CVE-2024-23897Perform with massive Jenkins Reading-2-RCE★ 2Ap0dexMe02024-02-19CandidatePoC-in-GitHub · pulentoski/CVE-2024-23897-Arbitrary-file-readUn script realizado en python para atumatizar la vulnerabilidad CVE-2024-23897★ 0pulentoski2024-02-20CandidatePoC-in-GitHub · Nebian/CVE-2024-23897Scraping tool to ennumerate directories or files with the CVE-2024-23897 vulnerability in Jenkins.★ 1Nebian2024-02-21CandidatePoC-in-GitHub · JAthulya/CVE-2024-23897Jenkins CVE-2024-23897: Arbitrary File Read Vulnerability★ 1JAthulya2024-05-03CandidatePoC-in-GitHub · murataydemir/CVE-2024-23897[CVE-2024-23897] Jenkins CI Authenticated Arbitrary File Read Through the CLI Leads to Remote Code Execution (RCE)★ 0murataydemir2024-05-07CandidatePoC-in-GitHub · Maalfer/CVE-2024-23897Poc para explotar la vulnerabilidad CVE-2024-23897 en versiones 2.441 y anteriores de Jenkins, mediante la cual podremos leer archivos internos del sistema sin estar autenticados★ 13Maalfer2024-05-16CandidatePoC-in-GitHub · Surko888/Surko-Exploit-Jenkins-CVE-2024-23897Un exploit con el que puedes aprovecharte de la vulnerabilidad (CVE-2024-23897)★ 0Surko8882024-05-26CandidatePoC-in-GitHub · cc3305/CVE-2024-23897CVE-2024-23897 exploit script★ 0cc33052024-07-28CandidatePoC-in-GitHub · verylazytech/CVE-2024-23897POC - Jenkins File Read Vulnerability - CVE-2024-23897★ 10verylazytech2024-09-30CandidatePoC-in-GitHub · D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins★ 4D1se02024-12-08CandidatePoC-in-GitHub · slytechroot/CVE-2024-23897Jenkins RCE Arbitrary File Read CVE-2024-23897★ 0slytechroot2025-03-23CandidatePoC-in-GitHub · brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo★ 0brandonhjh2025-03-28CandidatePoC-in-GitHub · tvasari/CVE-2024-23897Jenkins CLI arbitrary read (CVE-2024-23897 applies to versions below 2.442 and LTS 2.426.3)★ 0tvasari2025-04-04CandidatePoC-in-GitHub · Fineken/Jenkins-CVE-2024-23897-Lab★ 2Fineken2025-07-24CandidatePoC-in-GitHub · classic130/CVE-2024-23897-Jenkins-4.441★ 0classic1302025-07-29CandidatePoC-in-GitHub · amalpvatayam67/day03-jenkins-23897Jenkins CLI arbitrary file read (CVE-2024-23897)★ 0amalpvatayam672025-09-10CandidatePoC-in-GitHub · hybinn/CVE-2024-23897★ 0hybinn2025-10-06CandidatePoC-in-GitHub · aadi0258/Exploit-CVE-2024-23897★ 0aadi02582025-10-26CandidatePoC-in-GitHub · harekrishnarai/CVE-2024-23897-test-windows★ 0harekrishnarai2025-11-11CandidatePoC-in-GitHub · vmc8ll/poc-CVE-2024-23897CVE-2024-23897: Jenkins Arbitrary File Read Lead to RCE★ 0vmc8ll2026-03-03CandidatePoC-in-GitHub · w41l3r/jenkins_scanFind jenkins environment and checks for CVE-2024-23897★ 0w41l3r2026-04-23CandidatePoC-in-GitHub · rivaedoardo62-boop/cve-2024-23897-jenkins-pocSelf-contained Docker reproduction and analysis of CVE-2024-23897, the Jenkins CLI arbitrary file read via the args4j @-syntax argument expansion.★ 0rivaedoardo62-boop2026-06-16CandidatePoC-in-GitHub · Dungsocool/CVE-2024-23897★ 0Dungsocool2026-07-20CandidatePoC-in-GitHub · razureink/cve-2024-23897-jenkins_lfi_reproductionReproduction of cve-2024-23897-jenkins_lfi_reproduction★ 0razureink2026-07-24CandidatePoC-in-GitHub · dheeraj-jayaswal/CICD-Goat-Vapt-WriteupFull VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.★ 1dheeraj-jayaswal2026-07-31CandidatePoC-in-GitHub · MachiavelliII/CVE-2024-23897Jenkins CVE-2024-23897 — CSRF-crumb aware PoC★ 0MachiavelliII2026-08-28Candidate