Skip to content
argo-workflowsGHSA-rc7p-gmvh-xfx2

Attack on Kubernetes via Misconfigured Argo Workflows

MediumPublished Aug 2, 2021

### Impact Users running using the Argo Server with `--auth-mode=server` (which is the default < v3.0.0) AND have exposed their UI to the Internet may allow remote users to execute arbitrary code on their cluster, e.g. crypto-mining. ### Resolution * Do not expose your user interface to the Internet. * Change configuration. `--auth-mode=client`. For users using an older 2.x version of Argo Server, consider upgrading to Argo Server version 3.x or later.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/argoproj/argo-workflows
Go
all versionsNo fix yet
Details and references

More argo-workflows advisories

All argo-workflows
Advisory
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows
UnratedNov 5, 2025
Argo Workflows Allows Access to Archived Workflows with Fake Token in `client`...
UnratedDec 2, 2024
argo-workflows: denial of service
UnratedOct 30, 2024
Workflow re-write vulnerability using input parameter in github.com/argoproj/argo-workflows
UnratedAug 21, 2024
argo-workflows: privilege escalation
UnratedAug 21, 2024
Argo Server TLS requests could be forged by attacker with network access in github.com/argoproj/argo-workflows
UnratedAug 21, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.