CVE 10 CRITICAL

Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths_CVE-2026-32604

10 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.

AI Analysis

Spinnaker is vulnerable to Remote Code Execution (RCE) due to improper sanitization of user input on branch and paths when using gitrepo artifact types.

Basic Information

ID CVE-2026-32604
Source GitHub_M
Published Apr 20, 2026 at 20:00
Modified Apr 20, 2026 at 20:07

Affected Product

Vendor spinnaker
Product spinnaker
Version < 2026.0.1
Affected Versions spinnaker spinnaker < 2026.0.1
spinnaker spinnaker < 2025.4.2
spinnaker spinnaker < 2025.3.2
spinnaker spinnaker < 2026.1.0

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor Spinnaker
Product Spinnaker
Version < 2026.0.1, < 2025.4.2, < 2025.3.2, < 2026.1.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.