GHSA-xrqc-7xgx-c9vh

Suggest an improvement
Source
https://github.com/advisories/GHSA-xrqc-7xgx-c9vh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-xrqc-7xgx-c9vh/GHSA-xrqc-7xgx-c9vh.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-xrqc-7xgx-c9vh
Aliases
Downstream
CGA (33)
MINI (6)
Related
Published
2025-12-09T17:17:22Z
Modified
2026-07-17T20:59:12Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
RCE via ZipSlip and symbolic links in argoproj/argo-workflows
Details

Summary

The patch deployed against CVE-2025-62156 is ineffective against malicious archives containing symbolic links.

Details

The untar code that handles symbolic links in archives is unsafe. Concretely, the computation of the link's target and the subsequent check are flawed: https://github.com/argoproj/argo-workflows/blob/5291e0b01f94ba864f96f795bb500f2cfc5ad799/workflow/executor/executor.go#L1034-L1037

PoC

  1. Create a malicious archive containing two files: a symbolik link with path "./work/foo" and target "/etc", and a normal text file with path "./work/foo/hostname".
  2. Deploy a workflow like the one in https://github.com/argoproj/argo-workflows/security/advisories/GHSA-p84v-gxvw-73pf with the malicious archive mounted at /work/tmp.
  3. Submit the workflow and wait for its execution.
  4. Connect to the corresponding pod and observe that the file "/etc/hostname" was altered by the untar operation performed on the malicious archive. The attacker can hence alter arbitrary files in this way.

Impact

The attacker can overwrite the file /var/run/argo/argoexec with a script of their choice, which will be executed at the pod's start.

Database specific
{
    "cwe_ids": [
        "CWE-23",
        "CWE-59",
        "CWE-78"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-12-09T17:17:22Z",
    "nvd_published_at": "2025-12-09T21:16:00Z",
    "severity": "HIGH"
}
References

Affected packages

Go
github.com/argoproj/argo-workflows/v3

Package

Name
github.com/argoproj/argo-workflows/v3
View open source insights on deps.dev
Purl
pkg:golang/github.com/argoproj/argo-workflows/v3

Affected ranges

Type
SEMVER
Events
Introduced
3.7.0
Fixed
3.7.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-xrqc-7xgx-c9vh/GHSA-xrqc-7xgx-c9vh.json"
github.com/argoproj/argo-workflows/v3

Package

Name
github.com/argoproj/argo-workflows/v3
View open source insights on deps.dev
Purl
pkg:golang/github.com/argoproj/argo-workflows/v3

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.6.14

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-xrqc-7xgx-c9vh/GHSA-xrqc-7xgx-c9vh.json"
github.com/argoproj/argo-workflows

Package

Name
github.com/argoproj/argo-workflows
View open source insights on deps.dev
Purl
pkg:golang/github.com/argoproj/argo-workflows

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.5.3-rc4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-xrqc-7xgx-c9vh/GHSA-xrqc-7xgx-c9vh.json"