CVE-2026-32604
Impact
A bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily.
Workarounds
Disable the gitrepo artifact types.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/spinnaker/spinnaker/security/advisories/GHSA-x3j7-7pgj-h87r, https://nvd.nist.gov/vuln/detail/CVE-2026-32604, https://github.com/spinnaker/spinnaker, https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2025.3.2, https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2025.4.2, https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2026.0.1, https://github.com/spinnaker/spinnaker/releases/tag/spinnaker-release-2026.0.2
