CVE-2026-32604
Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
Vexday Risk Score
28Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 10EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
20 abr 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Produtos afetados
spinnaker · spinnakerQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2025.3.2https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2025.4.2https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2026.0.1https://github.com/spinnaker/spinnaker/security/advisories/GHSA-x3j7-7pgj-h87rhttps://zeropath.com/blog/spinnaker-rce-production-compromise