CVE-2025-66626 - CVE House
Back to Database
Status published High CVE-2025-66626

argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links

Vulnerability Description

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions 3.6.13 and below and versions 3.7.0 through 3.7.4, contain unsafe untar code that handles symbolic links in archives. Concretely, the computation of a link's target and the subsequent check are flawed. An attacker can overwrite the file /var/run/argo/argoexec with a script of their choice, which would be executed at the pod's start. The patch deployed against CVE-2025-62156 is ineffective against malicious archives containing symbolic links. This issue is fixed in versions 3.6.14 and 3.7.5.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66626

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

argo-workflows
Vulnerable Versions:
github.com/argoproj/argo-workflows/v3 >= 3.7.0, < 3.7.5, github.com/argoproj/argo-workflows/v3 < 3.6.14, github.com/argoproj/argo-workflows <= 2.5.3-rc4

Timeline

Official Publish: December 9th, 2025
Last Modified: December 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Weaknesses (CWE)