Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p84v-gxvw-73pf | Argo Workflow has a Zipslip Vulnerability |
Fri, 06 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj argo Workflows
|
|
| CPEs | cpe:2.3:a:argoproj:argo_workflows:*:*:*:*:*:go:*:* | |
| Vendors & Products |
Argo Workflows Project
Argo Workflows Project argo Workflows |
Argoproj argo Workflows
|
Mon, 17 Nov 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argo Workflows Project
Argo Workflows Project argo Workflows |
|
| CPEs | cpe:2.3:a:argo_workflows_project:argo_workflows:*:*:*:*:*:kubernetes:*:* | |
| Vendors & Products |
Argo Workflows Project
Argo Workflows Project argo Workflows |
Mon, 20 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj
Argoproj argo-workflows |
|
| Vendors & Products |
Argoproj
Argoproj argo-workflows |
Thu, 16 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 14 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 contain a Zip Slip path traversal vulnerability in artifact extraction. During artifact extraction the unpack/untar logic (workflow/executor/executor.go) uses filepath.Join(dest, filepath.Clean(header.Name)) without validating that header.Name stays within the intended extraction directory. A malicious archive entry can supply a traversal or absolute path that, after cleaning, overrides the destination directory and causes files to be written outside the /work/tmp extraction path and into system directories such as /etc inside the container. The vulnerability enables arbitrary file creation or overwrite in system configuration locations (for example /etc/passwd, /etc/hosts, /etc/crontab), which can lead to privilege escalation or persistence within the affected container. Update to 3.6.12 or 3.7.3 to remediate the issue. | |
| Title | argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwrite | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-14T16:04:24.519Z
Reserved: 2025-10-07T16:12:03.424Z
Link: CVE-2025-62156
Updated: 2025-10-14T16:04:21.505Z
Status : Analyzed
Published: 2025-10-14T15:16:12.683
Modified: 2026-02-06T20:49:29.827
Link: CVE-2025-62156
OpenCVE Enrichment
Updated: 2025-10-20T15:49:39Z
Github GHSA