Database/Container, Kubernetes & orchestration
Argo Workflows (Argo Server, artifact directory listing renderer): Object names are printed into the artifact directory
Impact
Object names are printed into the artifact directory listing HTML without escaping, and those names come from whatever files a workflow wrote. Any tenant who can run a workflow plants stored JavaScript that executes under the Argo Server origin in another user's browser, then drives the Argo API with that victim's privileges - submitting workflows, reading templates, deleting other tenants' runs.
Who can reach it
A tenant with workflow-submit rights plants the payload; an admin or another tenant triggers it by browsing the artifact listing in the Argo UI.
What to do
Upgrade to 3.6.17 or 3.7.8 and restart Argo Server. Until then, tell operators not to browse artifact directory listings for workflows submitted by untrusted tenants, and consider a CSP at the ingress in front of the UI.
References
Related entries
- containerd: Numeric User directive that fails 32-bit parsing is treated as a username, changing the effective UIDCVE-2026-46680 · containerdHigh
- cert-manager: Challenge resource handling flaw in cert-manager 1.18.0-1.19.5 and 1.20.xCVE-2026-62290 · cert-managerHigh
- Cilium (SDS secret sync for L7 network policies): A tenant confined to their own namespace reaches across and rewritesNCVD-2026-046-cilium-sds-secret-sync-for-l7-ne · Cilium (SDS secret sync for L7 network policies)High
- Harbor: SQL injection via user-groupsCVE-2019-19029 · HarborHigh
- Rancher: restricted-admin role escalates to full adminCVE-2021-36784 · RancherHigh
- Cilium: Debug mode logs the contents of the cilium-secrets namespace, including TLS private keysCVE-2023-29002 · CiliumHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.