{"id":"CVE-2025-62157","title":"Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes","summary":"Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-522"],"vendor":"argoproj","product":"argo_workflows","affected":["argo_workflows < 3.6.12","argo_workflows >= 3.7.0, < 3.7.3"],"patched":["argo_workflows 3.7.3"],"published":"2025-10-14","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-62157","references":[{"url":"https://github.com/argoproj/argo-workflows/commit/18ad5138b6bcb2aba04e00b4ec657bc6b8fad8df","label":"security-advisories@github.com"},{"url":"https://github.com/argoproj/argo-workflows/commit/bded09fe4abd37cb98d7fc81b4c14a6f5034e9ab","label":"security-advisories@github.com"},{"url":"https://github.com/argoproj/argo-workflows/security/advisories/GHSA-c2hv-4pfj-mm2r","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00466,"epssPercentile":0.38283,"ingestedAt":"2026-10-08T11:31:27.386Z","slug":"CVE-2025-62157","body":"## Overview\n\nArgo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. An attacker with permissions to read pod logs in a namespace running Argo Workflows can read the workflow-controller logs and obtain credentials to the artifact repository. Update to versions 3.6.12 or 3.7.3 to remediate the vulnerability. No known workarounds exist.\n\n## Affected\n\n- `argo_workflows < 3.6.12`\n- `argo_workflows >= 3.7.0, < 3.7.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `argo_workflows 3.7.3`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}