Argo Workflows affected by stored XSS in the artifact directory listing
Published Jan 21, 2026
7.3
HIGHCVSS 4.0
EPSS 0.40%
Description
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbitrary JavaScript in another user’s browser under the Argo Server origin, enabling API actions with the victim’s privileges. Versions 3.6.17 and 3.7.8 fix the issue.
Affected products
-
- Version < 3.6.17StatusaffectedConstraints-
- Version >= 3.7.0, < 3.7.8StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Argoproj | Argo-Workflows | n/a |
|
- < 3.6.17
- ≥ 3.7.0 · < 3.7.8
No data.
Red Hat OpenShift AI (RHOAI)
rhoai/odh-data-science-pipelines-argo-argoexec-rhel8
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-data-science-pipelines-argo-argoexec-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-api-server-v2-rhel8
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-api-server-v2-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-driver-rhel8
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-driver-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-launcher-rhel8
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-launcher-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-data-science-pipelines-argo-argoexec-rhel8 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-data-science-pipelines-argo-argoexec-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-api-server-v2-rhel8 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-api-server-v2-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-driver-rhel8 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-driver-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-launcher-rhel8 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-launcher-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9 | Affected | n/a |
github.com/argoproj/argo-workflows/v3
Go
Introduced 0 Fixed 3.6.17github.com/argoproj/argo-workflows/v3
Go
Introduced 3.7.0 Fixed 3.7.8github.com/argoproj/argo-workflows
Go
Introduced 0 Fixed not fixedgithub.com/argoproj/argo-workflows/v2
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/argoproj/argo-workflows/v3 | 0 | 3.6.17 |
| Go | github.com/argoproj/argo-workflows/v3 | 3.7.0 | 3.7.8 |
| Go | github.com/argoproj/argo-workflows | 0 | not fixed |
| Go | github.com/argoproj/argo-workflows/v2 | 0 | not fixed |
Remediation
Red Hat statement
This is an IMPORTANT vulnerability. A stored Cross-Site Scripting (XSS) flaw in Argo Workflows' artifact directory listing allows a workflow author to execute arbitrary JavaScript in another user's browser. This could lead to privilege escalation and information disclosure within Red Hat OpenShift AI, as an attacker could perform actions with the victim's privileges.
References (12)
- https://access.redhat.com/security/cve/CVE-2026-23960 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2431881 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-3596 Advisory
- https://github.com/advisories/GHSA-cv78-6m8q-ph82 Advisory
- https://github.com/argoproj/argo-workflows/blob/9872c296d29dcc5e9c78493054961ede9fc30797/server/artifacts/artifact_server.go#L194-L244 x_refsource_MISCProduct
- https://github.com/argoproj/argo-workflows/commit/159a5c56285ecd4d3bb0a67aeef4507779a44e17 x_refsource_MISCPatch
- https://github.com/argoproj/argo-workflows/releases/tag/v3.6.17 x_refsource_MISCProductRelease Notes
- https://github.com/argoproj/argo-workflows/releases/tag/v3.7.8 x_refsource_MISCProductRelease Notes
- https://github.com/argoproj/argo-workflows/security/advisories/GHSA-cv78-6m8q-ph82 x_refsource_CONFIRMExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-23960
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23960.json
- https://www.cve.org/CVERecord?id=CVE-2026-23960
Change history (0)
No recorded changes yet.