Path traversal in Argo Workflows - CVE-2025-62156

 

Path traversal in Argo Workflows - CVE-2025-62156

Published: December 9, 2025


Vulnerability identifier: #VU119403
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62156
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences within the unpack() function. A remote user can upload a specially crafted .zip archive to the application and overwrite arbitrary files on the system outside of the allowed directory. 


Affected software

Argo Workflows
Red Hat OpenShift AI (RHOAI)

How to mitigate CVE-2025-62156

Install updates from vendor's website.

Argo Workflows - addressed in versions 3.6.12, 3.7.3
Red Hat OpenShift AI (RHOAI) - update to 2.22.3

External References

Related Security Bulletins