Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
Critical severity
GitHub Reviewed
Published
Apr 20, 2026
in
spinnaker/spinnaker
•
Updated Apr 21, 2026
Package
Affected versions
< 2026.0.1
Patched versions
2026.0.1
Description
Published by the National Vulnerability Database
Apr 20, 2026
Published to the GitHub Advisory Database
Apr 21, 2026
Reviewed
Apr 21, 2026
Last updated
Apr 21, 2026
Impact
A bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily.
Workarounds
Disable the gitrepo artifact types.
References