CVE-2026-32604
Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 10EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
20 abr 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Productos afectados
spinnaker · spinnaker¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2025.3.2https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2025.4.2https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2026.0.1https://github.com/spinnaker/spinnaker/security/advisories/GHSA-x3j7-7pgj-h87rhttps://zeropath.com/blog/spinnaker-rce-production-compromise