Stored XSS Vulnerability in Argo Workflows by Argo Project
CVE-2026-23960
What is CVE-2026-23960?
Argo Workflows, an open-source container-native workflow engine designed for orchestrating parallel jobs on Kubernetes, suffers from a stored XSS vulnerability in its artifact directory listing. This flaw, present in versions prior to 3.6.17 and 3.7.8, allows any workflow author to embed malicious JavaScript that executes in the context of another user's browser when accessing affected pages under the Argo Server origin. As a result, it may enable the attacker to perform API actions with the victim's privileges, significantly compromising user account security. The issue is addressed in the aforementioned versions, highlighting the importance of keeping systems up-to-date.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
argo-workflows < 3.6.17 < 3.6.17
argo-workflows >= 3.7.0, < 3.7.8 < 3.7.0, 3.7.8
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
