argo-workflowsGO-2025-4024
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows
UnratedCVE-2025-62157 · Published Nov 5, 2025 · updated Feb 4, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/argoproj/argo-workflows Go | all versions | No fix yet |
Details and references
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows
- Severity from
- no source yet
- Also known as
- BIT-argo-workflows-2025-62157, CVE-2025-62157, GHSA-c2hv-4pfj-mm2r
More argo-workflows advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 52025 | Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows CVE-2025-62156Unratedno fix yet | Unrated | No fix yet |
| Dec 92025 | RCE via ZipSlip and symbolic links in argoproj/argo-workflows CVE-2025-66626High8.1no fix yet | High8.1 | No fix yet |
| Jan 21 | Argo Workflows affected by stored XSS in the artifact directory listing CVE-2026-23960Highno fix yet | High | No fix yet |
| Mar 11 | Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode CVE-2026-31892Highno fix yet | High | No fix yet |
| Mar 12 | Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows CVE-2026-28229Unratedno fix yet | Unrated | No fix yet |
| Jun 25 | Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure in github.com/argoproj/argo-workflows CVE-2026-42296High8.1no fix yet | High8.1 | No fix yet |