Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 10epss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
spinnaker · spinnakerReferences
https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2025.3.2https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2025.4.2https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2026.0.1https://github.com/spinnaker/spinnaker/security/advisories/GHSA-x3j7-7pgj-h87rhttps://zeropath.com/blog/spinnaker-rce-production-compromise