Junglewise Threat Intelligence

CVE-2026-23960: Argo Workflows stored XSS in artifact directory listing

CVE-2026-23960 · Severity: medium · CVSS 5.4 · Published 2026-01-21

Technologies: github.com/argoproj/argo-workflows/v3 (Go), github.com/argoproj/argo-workflows/v2 (Go), Argo Project Argo Workflows, github.com/argoproj/argo-workflows (Go). Vendors: Go, Argo Project, Red Hat.

Executive brief

Argo Workflows, a tool used to manage complex computing tasks on Kubernetes, contains a security flaw in how it displays file directories. An attacker with the ability to create workflows can inject malicious scripts that run in the browsers of other users, such as administrators. This could allow the attacker to perform unauthorized actions or access sensitive data using the victim's account permissions.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Argo Workflows artifact directory listing. The root cause is improper neutralization of input during the generation of the web page for artifact listings in 'artifact_server.go'. An attacker with workflow creation privileges (PR:L) can craft malicious artifact names or paths that, when viewed by another user (UI:R), execute arbitrary JavaScript under the Argo Server origin. This can be leveraged to perform API requests with the victim's authorization. The issue is resolved in versions 3.6.17 and 3.7.8 by implementing proper HTML templating and escaping.

Affected products

  • argoproj Argo Workflows < 3.6.17, >= 3.7.0, < 3.7.8
  • Red Hat Red Hat OpenShift AI (RHOAI)

Timeline

  • 2026-01-21: disclosed
  • 2026-01-21: patched: Versions 3.6.17 and 3.7.8 released
  • 2026-01-21: advisory

References

Related threats