VDB
Sign up
CRITICAL9.9

GHSA-69rw-45wj-g4v6

Spinnaker: RCE via expression parsing due to unrestricted context handling

Quick fix

GHSA-69rw-45wj-g4v6 — io.spinnaker.echo:echo-pipelinetriggers: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2026.0.1</version> for io.spinnaker.echo:echo-pipelinetriggers

Details

Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically around expected artifacts. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, unlike orca, it was NOT restricting that context to a set of trusted classes, but allowing FULL JVM access. This enabled a user to use arbitrary java classes which allow deep access to the system. This enabled the ability to invoke commands, access files, etc. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable echo entirely.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.spinnaker.echo:echo-pipelinetriggers
Introduced in: 2026.0-0Fixed in: 2026.0.1
Fix# pom.xml: bump <version>2026.0.1</version> for io.spinnaker.echo:echo-pipelinetriggers
Maven/io.spinnaker.echo:echo-pipelinetriggers
Introduced in: 2025.4-0Fixed in: 2025.4.2
Fix# pom.xml: bump <version>2025.4.2</version> for io.spinnaker.echo:echo-pipelinetriggers
Maven/io.spinnaker.echo:echo-pipelinetriggers
Introduced in: 0Fixed in: 2025.3.2
Fix# pom.xml: bump <version>2025.3.2</version> for io.spinnaker.echo:echo-pipelinetriggers

References