VDB
Sign up
CRITICAL9.9

GHSA-x3j7-7pgj-h87r

Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths

Quick fix

GHSA-x3j7-7pgj-h87r — io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2026.0.1</version> for io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo

Details

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo
Introduced in: 0Fixed in: 2026.0.1
Fix# pom.xml: bump <version>2026.0.1</version> for io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo

References