Improper Neutralization of Special Elements in Output Used by a Downstream Component in Argo Workflows - #VU126902
Published: August 4, 2021 / Updated: April 23, 2026
Argo Workflows
Argo
Description
The vulnerability allows a remote user to modify workflows.
The vulnerability exists due to improper neutralization of special elements in expression templates in workflow input parameter handling when processing user-supplied input parameters. A remote user can supply a crafted input parameter to modify workflows.
Only deployments that allow end-users to set input parameters are affected.