Privilege Escalation Vulnerability in Argo Events for Kubernetes
CVE-2025-32445

10CRITICAL

Key Information:

Vendor

Argoproj

Vendor
CVE Published:
15 April 2025

What is CVE-2025-32445?

Argo Events is an open-source framework designed for event-driven workflow automation on Kubernetes. A vulnerability exists that allows a user with permissions to create or modify EventSource and Sensor custom resources to potentially gain unauthorized privileged access to the host system and Kubernetes cluster. By manipulating the container specifications in the EventSource or Sensor CRs, such as command, args, and securityContext, users can escalate their privileges without needing direct administrative rights. This issue has been resolved in version 1.9.6.

Affected Version(s)

argo-events < 1.9.6

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.