CVE-2025-62157 - CVE House
Back to Database
Status published High CVE-2025-62157

Argo Workflows exposes artifact repository credentials in workflow-controller logs

Vulnerability Description

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. An attacker with permissions to read pod logs in a namespace running Argo Workflows can read the workflow-controller logs and obtain credentials to the artifact repository. Update to versions 3.6.12 or 3.7.3 to remediate the vulnerability. No known workarounds exist.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62157

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

argo-workflows
Vulnerable Versions:
>= 3.7.0, < 3.7.3, < 3.6.12

Timeline

Official Publish: October 14th, 2025
Last Modified: October 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)