📦 Argo Workflows

by Argoproj

🔍 What is Argo Workflows?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-66626

HIGH CVSS 8.1 Dec 9, 2025

This vulnerability in Argo Workflows allows attackers to overwrite the argoexec file with malicious scripts via specially crafted archives containing symbolic links. When exploited, this leads to arbi...

CVE-2025-62156

HIGH CVSS 8.1 Oct 14, 2025

Argo Workflows contains a Zip Slip path traversal vulnerability in artifact extraction that allows attackers to write arbitrary files outside the intended extraction directory. This can lead to system...

CVE-2024-53862

HIGH CVSS 7.5 Dec 2, 2024

This vulnerability in Argo Workflows allows attackers to retrieve archived workflows without proper authentication. When using client or SSO authentication modes, attackers can bypass token validation...

CVE-2022-29164

HIGH CVSS 7.1 May 6, 2022

This vulnerability in Argo Workflows allows authenticated attackers to create malicious workflows that generate HTML artifacts containing scripts. When victims open these artifacts, the scripts execut...

CVE-2026-23960

MEDIUM CVSS 5.4 Jan 21, 2026

This stored cross-site scripting (XSS) vulnerability in Argo Workflows allows workflow authors to inject malicious JavaScript into artifact directory listings. When other users view these listings, th...

CVE-2025-62157

MEDIUM CVSS 6.5 Oct 14, 2025

Argo Workflows versions before 3.6.12 and 3.7.0-3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. Attackers with pod log read permissions can steal these crede...