Skip to content
Threat Feed
high advisory

Remote Code Execution in Spinnaker rosco-manifests via Kustomize

The Spinnaker rosco-manifests package is vulnerable to remote code execution (RCE) via improper YAML processing during Kustomize bake operations, allowing attackers to execute arbitrary code on rosco pods.

CVE search metadata

CVE search record: CVE-2026-55175. Severity: high. CVSS: 7.5. EPSS: 1.06%. KEV: no. Product: rosco-manifests (< 2025.3.4, 2025.4.0-2025.4.3, 2026.0.0-2026.0.2, 2026.1.0). Brief: Remote Code Execution in Spinnaker rosco-manifests via Kustomize. Brief link: https://feed.craftedsignal.io/briefs/2026-08-spinnaker-rosco-rce/

Spinnaker's rosco-manifests package is susceptible to a high-severity remote code execution (RCE) vulnerability, tracked as CVE-2026-55175. The issue arises from improper YAML processing when the system performs Kustomize bake operations. An attacker capable of influencing the Kustomize input can trigger unsafe tag processing, resulting in the execution of arbitrary commands within the context of the rosco pods. This vulnerability is specific to the Kustomize provider within Spinnaker. Defenders should prioritize updating to the fixed versions or disabling Kustomize bake operations until patches can be applied. The vulnerability affects multiple versions of rosco-manifests across the 2025 and 2026 release cycles.

Impact

Successful exploitation allows for remote code execution on the rosco pod, potentially leading to unauthorized system access, data exfiltration, or further compromise of the Spinnaker deployment environment. The vulnerability impacts organizations using Spinnaker for continuous delivery and CI/CD orchestration, particularly those utilizing Kustomize for manifest generation.

Recommendation

  • Upgrade rosco-manifests to versions 2025.3.4, 2025.4.4, 2026.0.3, 2026.1.1, or later to remediate CVE-2026-55175.
  • Disable Kustomize bake operations in the Spinnaker configuration as an immediate workaround if patching cannot be performed immediately.
  • Audit logs for the rosco-manifests service to identify anomalous Kustomize bake requests or suspicious process execution originating from the rosco pod.

Immediate actions

Disable Kustomize bake operations in Spinnaker as a temporary mitigation

Security Engineering 24h

Mitigations

Upgrade rosco-manifests to non-vulnerable versions as specified in the advisory

immediate IT Operations

CVE-2026-55175