Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
Critical severity
GitHub Reviewed
Published
Apr 20, 2026
in
spinnaker/spinnaker
•
Updated Apr 27, 2026
Package
Affected versions
< 2026.0.1
Patched versions
2026.0.1
Description
Published by the National Vulnerability Database
Apr 20, 2026
Published to the GitHub Advisory Database
Apr 21, 2026
Reviewed
Apr 21, 2026
Last updated
Apr 27, 2026
Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.
References