10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.
AI Analysis
Spinnaker is vulnerable to Remote Code Execution (RCE) due to improper sanitization of user input on branch and paths when using gitrepo artifact types.
Basic Information
ID
CVE-2026-32604
Source
GitHub_M
Published
Apr 20, 2026 at 20:00
Modified
Apr 20, 2026 at 20:07
Affected Product
Vendor
spinnaker
Product
spinnaker
Version
< 2026.0.1
Affected Versions
spinnaker spinnaker < 2026.0.1
spinnaker spinnaker < 2025.4.2
spinnaker spinnaker < 2025.3.2
spinnaker spinnaker < 2026.1.0
spinnaker spinnaker < 2025.4.2
spinnaker spinnaker < 2025.3.2
spinnaker spinnaker < 2026.1.0
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
Spinnaker
Product
Spinnaker
Version
< 2026.0.1, < 2025.4.2, < 2025.3.2, < 2026.1.0