CVE-2025-62157: Argo Workflows exposes artifact repository credentials in workflow-controller logs

Published Oct 14, 2025
·
Updated

Summary An attacker who has permissions to read logs from pods in a namespace with Argo Workflow can read workflow-controller logs and get credentials to the artifact repository.

Details An attacker, by reading the logs of the workflow controller pod, can access the artifact repository, and steal, delete or modify the data that resides there. The workflow-controller logs show the credentials in plaintext.

<img width="1366" alt="screen" src="https://github.com/user-attachments/assets/5642b2be-edcf-4050-bf47-747d05352698" />

Impact An attacker with access to pod logs in the argo namespace can extract plaintext credentials from the workflow-controller logs and gain access to the artifact repository. This can lead to: - Data exfiltration – theft of sensitive or proprietary artifacts - Data tampering – modification of workflows or artifacts - Data destruction – deletion of stored artifacts, leading to potential loss of critical data or pipeline failure

Other sources

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. An attacker with permissions to read pod logs in a namespace running Argo Workflows can read the workflow-controller logs and obtain credentials to the artifact repository. Update to versions 3.6.12 or 3.7.3 to remediate the vulnerability. No known workarounds exist.

MITRE

Affected Software

5 affected componentsFixes available
Argo Workflows<3.6.12, >=3.7.0<3.7.2
go/github.com/argoproj/argo-workflows/v3<3.6.12
3.6.12
go/github.com/argoproj/argo-workflows/v3>=3.7.0<3.7.3
3.7.3
argoproj Argo Workflows Go<3.6.12
argoproj Argo Workflows Go>=3.7.0<3.7.3

Event History

Oct 14, 2025
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
RemedyAffected Software
Advisory Published
via GitHub·06:43 PM
Data Sourced
via GitHub·06:43 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-62157?

CVE-2025-62157 is rated as a high severity vulnerability due to the exposure of sensitive credentials in plaintext.

2

How do I fix CVE-2025-62157?

To remediate CVE-2025-62157, upgrade Argo Workflows to version 3.6.12 or later, or to version 3.7.3 and above.

3

What systems are affected by CVE-2025-62157?

CVE-2025-62157 affects Argo Workflows versions prior to 3.6.12 and between 3.7.0 and 3.7.2.

4

What type of vulnerability is CVE-2025-62157?

CVE-2025-62157 is a credential exposure vulnerability that reveals artifact repository credentials in logs.

5

What risks does CVE-2025-62157 pose to users?

CVE-2025-62157 may allow attackers to gain unauthorized access to the artifact repositories by exploiting the exposed plaintext credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203