GHSA-3fwg-9p8x-37mvHighCVSS 7.7

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in...

Published
September 20, 2026
Last Modified
September 20, 2026

🔗 CVE IDs covered (1)

📋 Description

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.

🔗 References (7)