Spinnaker Clouddriver RCE Vulnerability via Gitrepo Artifact Types

Vulnerability

A remote code execution vulnerability has been identified in Spinnaker's Clouddriver component, specifically within the 'clouddriver-artifacts-gitrepo' artifact type. This issue affects versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2. The vulnerability arises from improper sanitization of user input related to branches and paths, allowing a bad actor to execute arbitrary commands on the Clouddriver pods. Such exploitation could easily expose credentials, delete files, or inject resources.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on Clouddriver pods, with potential consequences including exposure of credentials, unauthorized file deletion, or injection of resources.

Remediation

Users can upgrade to Spinnaker versions 2026.1.0, 2026.0.1, 2025.4.2, or 2025.3.2, all of which include the necessary patch. Alternatively, as a temporary workaround, Gitrepo artifact types can be disabled.

Added: Apr 20, 2026, 9:30 PM
Updated: Apr 20, 2026, 9:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
0.0
relevance
6.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.