CVE-2025-32445
CVSS 3.1 Score 9.9 of 10 (high)
Details
Summary
CVE-2025-32445 is a vulnerability affecting Argo Events, an event-driven workflow automation framework for Kubernetes. This issue allows users with permission to create or modify EventSource and Sensor custom resources to gain privileged access to the host system and cluster, bypassing the need for direct administrative privileges. The vulnerability is due to the ability to customize the specification of containers in the corresponding orchestrated pods, including specifying properties such as command, args, and securityContext. A malicious user could exploit this by configuring these properties to gain privileged access to the cluster host. The vulnerability is resolved in version 1.9.6.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Argo-Events
Affected Vendors
- Argo Events