Improperly Controlled Modification of Dynamically-Determined Object Attributes Affecting github.com/argoproj/argo-workflows/workflow/util package, versions <4.0.6


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.36% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMARGOPROJARGOWORKFLOWSWORKFLOWUTIL-18016334
  • published19 Jul 2026
  • disclosed16 Jul 2026
  • creditfg0x0, 0xVijay, tonghuaroot

Introduced: 16 Jul 2026

CVE-2026-54526  (opens in a new tab)
CWE-915  (opens in a new tab)

How to fix?

Upgrade github.com/argoproj/argo-workflows/workflow/util to version 4.0.6 or higher.

Overview

Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes via the ArtifactGC.PodSpecPatch handling in workflow/util/merge.go. An attacker can override the artifact-GC pod’s spec by submitting a Workflow with spec.artifactGC.podSpecPatch under workflowTemplateRef in Strict or Secure mode, causing the controller to run attacker-chosen pod settings instead of the hardened defaults. That lets the attacker inject an arbitrary strategic merge patch into the artifact-GC pod, including changes such as a different container image, privileged settings, hostNetwork, or hostPath mounts. For users relying on Strict/Secure template referencing, this breaks the intended restriction and can expose the workflow’s service-account token and node resources.

CVSS Base Scores

version 4.0
version 3.1