7.3
/ 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbitrary JavaScript in another userโs browser under the Argo Server origin, enabling API actions with the victimโs privileges. Versions 3.6.17 and 3.7.8 fix the issue.
Basic Information
ID
CVE-2026-23960
Source
GitHub_M
Published
Jan 21, 2026 at 22:02
Modified
Jan 22, 2026 at 16:49
Affected Product
Vendor
argoproj
Product
argo-workflows
Version
< 3.6.17
Affected Versions
argoproj argo-workflows < 3.6.17
argoproj argo-workflows >= 3.7.0, < 3.7.8
argoproj argo-workflows >= 3.7.0, < 3.7.8
CWE Classification
References
- github.com /argoproj/argo-workflows/security/advisories/GHSA-cv78-6m8q-ph82
- github.com /argoproj/argo-workflows/commit/159a5c56285ecd4d3bb0a67aeef4507779a44e17
- github.com /argoproj/argo-workflows/blob/9872c296d29dcc5e9c78493054961ede9fc30797/server/artifacts/artifact_server.go
- github.com /argoproj/argo-workflows/releases/tag/v3.6.17
- github.com /argoproj/argo-workflows/releases/tag/v3.7.8