Argo Workflows versions 4.1.0 through 4.1.3 contain an...
High severity
Unreviewed
Published
Sep 20, 2026
to the GitHub Advisory Database
•
Updated Sep 20, 2026
Description
Published by the National Vulnerability Database
Sep 19, 2026
Published to the GitHub Advisory Database
Sep 20, 2026
Last updated
Sep 20, 2026
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.
References