Executive brief
Argo Workflows is an automation engine used to run complex parallel jobs on Kubernetes clusters. A security flaw allows users with basic workflow creation permissions to bypass security restrictions and run malicious code with elevated privileges. By injecting unauthorized configurations into the system's cleanup process, an attacker could gain access to sensitive service account tokens, access the host network, or run arbitrary commands on the underlying infrastructure.
Technical details
The vulnerability exists because the validation logic in 'workflow/util/merge.go' (ValidateUserOverrides and SanitizeUserWorkflowSpec) only inspects top-level fields of the WorkflowSpec via reflection. While the top-level 'PodSpecPatch' was restricted in a previous fix (CVE-2026-31892), the 'ArtifactGC' field was allow-listed wholesale. This allow-listed field contains a nested 'PodSpecPatch' sub-field that flows unvalidated into 'util.ApplyPodSpecPatch' on the artifact-GC pod. An attacker can use this to inject a strategic merge patch, enabling the creation of privileged containers, hostPath volumes, or hostNetwork access, effectively escaping the restrictions of a hardened WorkflowTemplate.
Affected products
- argoproj Argo Workflows < 3.7.15, >= 4.0.0 < 4.0.6
Timeline
- 2026-06-10: patched: Fixed in versions 3.7.15 and 4.0.6
- 2026-06-10: advisory: GitHub Security Advisory GHSA-48p8-g2fx-3wwm published
- 2026-07-16: disclosed: CVE-2026-54526 published to NVD
References
- https://github.com/argoproj/argo-workflows/commit/277e9cef0ad16d7eaaab253573d0695951a65dbd
- https://github.com/argoproj/argo-workflows/commit/358cc3968c8f06f1be0967e41df191088db0b662
- https://github.com/argoproj/argo-workflows/releases/tag/v3.7.15
- https://github.com/argoproj/argo-workflows/releases/tag/v4.0.6
- https://github.com/argoproj/argo-workflows/security/advisories/GHSA-48p8-g2fx-3wwm