{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rosco-manifests--2025.3.4-2025.4.0-2025.4.3-2026.0.0-2026.0.2-2026.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-55175"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rosco-manifests (\u003c 2025.3.4, 2025.4.0-2025.4.3, 2026.0.0-2026.0.2, 2026.1.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","ci-cd","spinnaker"],"_cs_type":"advisory","_cs_vendors":["Spinnaker"],"content_html":"\u003cp\u003eSpinnaker's rosco-manifests package is susceptible to a high-severity remote code execution (RCE) vulnerability, tracked as CVE-2026-55175. The issue arises from improper YAML processing when the system performs Kustomize bake operations. An attacker capable of influencing the Kustomize input can trigger unsafe tag processing, resulting in the execution of arbitrary commands within the context of the rosco pods. This vulnerability is specific to the Kustomize provider within Spinnaker. Defenders should prioritize updating to the fixed versions or disabling Kustomize bake operations until patches can be applied. The vulnerability affects multiple versions of rosco-manifests across the 2025 and 2026 release cycles.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for remote code execution on the rosco pod, potentially leading to unauthorized system access, data exfiltration, or further compromise of the Spinnaker deployment environment. The vulnerability impacts organizations using Spinnaker for continuous delivery and CI/CD orchestration, particularly those utilizing Kustomize for manifest generation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade rosco-manifests to versions 2025.3.4, 2025.4.4, 2026.0.3, 2026.1.1, or later to remediate CVE-2026-55175.\u003c/li\u003e\n\u003cli\u003eDisable Kustomize bake operations in the Spinnaker configuration as an immediate workaround if patching cannot be performed immediately.\u003c/li\u003e\n\u003cli\u003eAudit logs for the rosco-manifests service to identify anomalous Kustomize bake requests or suspicious process execution originating from the rosco pod.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:15:25Z","date_published":"2026-08-28T21:15:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-spinnaker-rosco-rce/","summary":"The Spinnaker rosco-manifests package is vulnerable to remote code execution (RCE) via improper YAML processing during Kustomize bake operations, allowing attackers to execute arbitrary code on rosco pods.","title":"Remote Code Execution in Spinnaker rosco-manifests via Kustomize","url":"https://feed.craftedsignal.io/briefs/2026-08-spinnaker-rosco-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Rosco-Manifests (\u003c 2025.3.4, 2025.4.0-2025.4.3, 2026.0.0-2026.0.2, 2026.1.0)","version":"https://jsonfeed.org/version/1.1"}