Container-Native Workflow Engine Vulnerability in Argo Workflows by Argo Project
CVE-2026-54526
8.9HIGH
What is CVE-2026-54526?
Argo Workflows, an open source container-native workflow engine for Kubernetes, has a vulnerability that allows users to inject arbitrary strategic merge patches into the artifact-GC pod. This issue arises from the incompleteness of the allow-list fix related to the WorkflowSpec.ArtifactGC field mapping. Affected versions prior to 3.7.15 and 4.0.6 inadequately validate user inputs for artifact garbage collection, potentially leading to exploitation through host path volumes, privilege escalation, and arbitrary command execution. Critical updates in versions 3.7.15 and 4.0.6 address this concern and should be applied immediately to ensure security.
Affected Version(s)
argo-workflows < 3.7.15 < 3.7.15
argo-workflows >= 4.0.0, < 4.0.6 < 4.0.0, 4.0.6
