UNKNOWN Go
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows
GO-2026-6223 · BIT-argo-workflows-2026-54526 · CVE-2026-54526 · GHSA-48p8-g2fx-3wwm
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows
References
- ADVISORY https://github.com/argoproj/argo-workflows/security/advisories/GHSA-48p8-g2fx-3wwm
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-54526
- FIX https://github.com/argoproj/argo-workflows/commit/277e9cef0ad16d7eaaab253573d0695951a65dbd
- FIX https://github.com/argoproj/argo-workflows/commit/358cc3968c8f06f1be0967e41df191088db0b662
- WEB https://github.com/argoproj/argo-workflows/releases/tag/v3.7.15
- WEB https://github.com/argoproj/argo-workflows/releases/tag/v4.0.6
Ready to move
Start Securing
Free, no credit card | First findings in minutes