Database/Container, Kubernetes & orchestration
Argo Workflows (workflow executor, tar extraction symlink handling): The patch for CVE-2025-62156 missed symlinks, so a
Impact
The patch for CVE-2025-62156 missed symlinks, so a crafted input artifact still escapes the extraction directory and writes anywhere the executor can reach. The executor container holds the workflow service account token and runs alongside the user's container, so an arbitrary write there converts a data-plane artifact into code execution inside Argo's own executor identity.
Who can reach it
Any user who can submit a workflow that consumes an attacker-supplied artifact, or who can plant an archive in a repository another tenant's workflow pulls from.
What to do
Upgrade to 3.6.14 or 3.7.5 and restart the controller so new pods get the fixed executor image. Do not stop at 3.6.12/3.7.3 - that is the incomplete fix for CVE-2025-62156.
References
Related entries
- Podman: kube play follows symlinks in Secret/ConfigMap volumes and overwrites host filesCVE-2025-9566 · Podman (podman kube play, Secret/ConfigMap volume mounts)High
- Moby: plugin privilege approval can be bypassed during docker plugin installCVE-2026-33997 · Moby / Docker Engine daemon (docker plugin install privilege comparison)High
- Argo Workflows (controller, hostNetwork / securityContext / serviceAccountName merge path): The first fix forCVE-2026-42296 · Argo Workflows (controller, hostNetwork / securityContext / serviceAccountName merge path)High
- containerd: On SELinux hosts, an unprivileged pod with a hostPath volume can gain full read/write to the host filesystemCVE-2021-43816 · containerdHigh
- Cilium: IPsec transparent encryption is cryptographically ineffectiveCVE-2024-28860 · CiliumHigh
- Nuclio controller: cron trigger headers and body are injected into the CronJob shell commandCVE-2026-52831 · Nuclio controller (cron trigger rendered into Kubernetes CronJob args)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.