GPU VulnDB

Database/Container, Kubernetes & orchestration

Argo Workflows (workflow executor, artifact unpack path handling): MULTI-TENANT ISOLATION: Archive entries with

CVE-2025-62156Container, Kubernetes & orchestrationGHSA-p84v-gxvw-73pfcurated

Impact

MULTI-TENANT ISOLATION: Archive entries with traversal paths escape the temporary unpack directory during artifact extraction, letting a crafted archive overwrite files outside it - including paths under /etc in the executor. Because the executor carries the workflow's Kubernetes identity, a poisoned input artifact turns into control over a component that other tenants' workflows also run through.

Who can reach it

Any user able to submit a workflow that pulls an attacker-controlled input artifact, or able to write into a shared artifact repository path.

What to do

Upgrade to 3.6.12 or 3.7.3, then immediately to 3.6.14 / 3.7.5 because the initial fix was bypassable via symlinks (CVE-2025-66626). Restart the controller so new workflow pods pick up the corrected executor.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.