VYPR

Workflows

by ArgoCD

Source repositories

CVEs (2)

  • CVE-2026-54526CriJul 16, 2026
    risk 0.57cvss 9.9epss 0.01

    Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because workflow/util/merge.go ValidateUserOverrides and SanitizeUserWorkflowSpec walk…

  • CVE-2021-37914MedAug 3, 2021
    risk 0.35cvss 6.5epss 0.01

    In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflows, an attacker may be able to disrupt a workflow because expression template output is evaluated.