Privilege Escalation Vulnerability in Argo Events for Kubernetes
CVE-2025-32445
10CRITICAL
What is CVE-2025-32445?
Argo Events is an open-source framework designed for event-driven workflow automation on Kubernetes. A vulnerability exists that allows a user with permissions to create or modify EventSource and Sensor custom resources to potentially gain unauthorized privileged access to the host system and Kubernetes cluster. By manipulating the container specifications in the EventSource or Sensor CRs, such as command, args, and securityContext, users can escalate their privileges without needing direct administrative rights. This issue has been resolved in version 1.9.6.
Affected Version(s)
argo-events < 1.9.6