CVE-2026-23960
Argo Workflows affected by stored XSS in the artifact directory listing in github.com/argoproj/argo-workflows
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/argoproj/argo-workflows/security/advisories/GHSA-cv78-6m8q-ph82, https://nvd.nist.gov/vuln/detail/CVE-2026-23960, https://github.com/argoproj/argo-workflows/commit/159a5c56285ecd4d3bb0a67aeef4507779a44e17, https://github.com/argoproj/argo-workflows/blob/9872c296d29dcc5e9c78493054961ede9fc30797/server/artifacts/artifact_server.go#L194-L244, https://github.com/argoproj/argo-workflows/releases/tag/v3.6.17, https://github.com/argoproj/argo-workflows/releases/tag/v3.7.8
