Privilege Escalation Vulnerability in Argo Events for Kubernetes
CVE-2025-32445
What is CVE-2025-32445?
Argo Events is an open-source framework designed for event-driven workflow automation on Kubernetes. A vulnerability exists that allows a user with permissions to create or modify EventSource and Sensor custom resources to potentially gain unauthorized privileged access to the host system and Kubernetes cluster. By manipulating the container specifications in the EventSource or Sensor CRs, such as command, args, and securityContext, users can escalate their privileges without needing direct administrative rights. This issue has been resolved in version 1.9.6.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
argo-events < 1.9.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
