Path traversal in Argo Workflows - #VU151674
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in the directory artifact materialization functionality of the S3, GCS, Azure Blob, and OSS artifact drivers when downloading directory artifacts from cloud object storage. A remote user can provide a crafted cloud object key containing directory traversal sequences to execute arbitrary code.
Exploitation requires a workflow configured to use a directory input artifact.