THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p68j-q7hf-3qcp (high) — Spinnaker: Improper yaml processing on kustomize bake operations

[GHSA] GHSA-p68j-q7hf-3qcp (high) — Spinnaker: Improper yaml processing on kustomize bake operations

medgithub_advisoriesPublished 2026-08-28

GHSA-p68j-q7hf-3qcp Severity: high CVE: CVE-2026-55175

Spinnaker: Improper yaml processing on kustomize bake operations

### Impact Kustomize bake operations allow unsafe tag processing. This can lead to RCE type exploits on the rosco pods when doing kustomize bakes. This ONLY is possible when using Kustomize. The simple solution is to block kustomize operations and instead use another provide

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p68j-q7hf-3qcp