CVE-2025-66626
argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links
描述
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions 3.6.13 and below and versions 3.7.0 through 3.7.4, contain unsafe untar code that handles symbolic links in archives. Concretely, the computation of a link's target and the subsequent check are flawed. An attacker can overwrite the file /var/run/argo/argoexec with a script of their choice, which would be executed at the pod's start. The patch deployed against CVE-2025-62156 is ineffective against malicious archives containing symbolic links. This issue is fixed in versions 3.6.14 and 3.7.5.
如何修補 CVE-2025-66626
要修補 CVE-2025-66626,請將受影響套件升級到下列已修補版本。
- —升級至 2.5.3 或更新版本
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —升級至 3.7.5 或更新版本
- —升級至 3.6.14 或更新版本
CVE-2025-66626 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(6)
- from 0, < 2.5.3, >= 3.0.0, < 3.6.14
- from 0, <= 2.5.3-rc4
- from 0
- from 0
- >= 3.7.0, < 3.7.5
- from 0, < 3.6.14, >= 3.7.0, < 3.7.5
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |