GHSA-69rw-45wj-g4v6
Spinnaker: RCE via expression parsing due to unrestricted context handling
Quick fix
GHSA-69rw-45wj-g4v6 — io.spinnaker.echo:echo-pipelinetriggers: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2026.0.1</version> for io.spinnaker.echo:echo-pipelinetriggersDetails
Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically around expected artifacts. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, unlike orca, it was NOT restricting that context to a set of trusted classes, but allowing FULL JVM access. This enabled a user to use arbitrary java classes which allow deep access to the system. This enabled the ability to invoke commands, access files, etc. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable echo entirely.
Are you affected?
Enter the version of the package you're using.
Affected packages
2026.0-0Fixed in: 2026.0.1# pom.xml: bump <version>2026.0.1</version> for io.spinnaker.echo:echo-pipelinetriggers2025.4-0Fixed in: 2025.4.2# pom.xml: bump <version>2025.4.2</version> for io.spinnaker.echo:echo-pipelinetriggers0Fixed in: 2025.3.2# pom.xml: bump <version>2025.3.2</version> for io.spinnaker.echo:echo-pipelinetriggersReferences
- https://github.com/spinnaker/spinnaker/security/advisories/GHSA-69rw-45wj-g4v6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-32613[ADVISORY]
- https://github.com/spinnaker/spinnaker[PACKAGE]
- https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2025.3.2[WEB]
- https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2025.4.2[WEB]
- https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2026.0.1[WEB]
- https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2026.0.2[WEB]
- https://zeropath.com/blog/spinnaker-rce-production-compromise[WEB]