Impact
Spinnaker’s Kustomize bake operation allows unsafe YAML tag processing in rosco manifests, a flaw classified as CWE‑502. During a bake an attacker can supply crafted YAML that is deserialized by rosco, enabling arbitrary code execution on the rosco pods. The vulnerability is limited to the Kustomize bake mechanism and does not automatically grant privilege escalation beyond the rosco environment; the impact is the ability to execute code within the containers that rely on these pods.
Affected Systems
All Spinnaker deployments running a rosco component before the following releases are affected: the 2026 release line prior to 2026.1.1, the 2026.0 line prior to 2026.0.3, the 2025.4 line prior to 2025.4.4, and the 2025.3 line prior to 2025.3.4. These versions run the vulnerable Kustomize bake operation and therefore expose rosco pods to users on earlier or intermediate releases that do not include the patched rosco component are also at risk.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is of medium‑high severity. The EPSS score of <1% indicates a low probability of active exploitation, and it is not listed in CISA’s KEV catalog. The attack vector is inferred to require an actor able to trigger a Kustomize bake against a rosco instance that this could/CD pipeline, or an external actor who gains access to that capability. code within the rosco pod, which in turn can affect the broader deployment by pivoting, persisting, or exfiltrating data.
OpenCVE Enrichment