github.com/argoproj/argo-events
Event-driven Automation Framework for Kubernetes
Activity
- Latest release
- 2mo ago
- Total releases
- 54
- Cadence
- ~35 days
- Last 12 months
- 4
Reach
- Stars
- 2.7k
Details
- First release
- Mar 13, 2019
| Version | Released | |
|---|---|---|
v1.9.11
patch
|
v1.9.11
patch
Dependencies (97)
+ 89 more |
|
v1.9.10
patch
|
v1.9.10
patch
Dependencies (95)
+ 87 more |
|
v1.9.9
patch
|
v1.9.9
patch
Dependencies (94)
+ 86 more |
|
v1.9.8
patch
|
v1.9.8
patch
Dependencies (94)
+ 86 more |
|
v1.9.7
patch
|
v1.9.7
patch
Dependencies (94)
+ 86 more |
|
v1.9.6
patch
|
v1.9.6
patch
Dependencies (93)
+ 85 more |
|
v1.9.5
patch
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.9.5
patch
Dependencies (89)
+ 81 more |
|
v1.9.4
patch
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.9.4
patch
Dependencies (89)
+ 81 more |
|
v1.9.3
patch
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.9.3
patch
Dependencies (89)
+ 81 more |
|
v1.9.2
patch
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.9.2
patch
Dependencies (89)
+ 81 more |
|
v1.9.1
minor
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.9.1
minor
Dependencies (88)
+ 80 more |
|
v1.9.0
minor
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.9.0
minor
Dependencies (88)
+ 80 more |
|
v1.8.1
minor
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.8.1
minor
Dependencies (87)
+ 79 more |
|
v1.8.0
minor
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.8.0
minor
Dependencies (86)
+ 78 more |
|
v1.7.6
patch
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.6
patch
Dependencies (84)
+ 76 more |
|
v1.7.5
patch
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.5
patch
Dependencies (84)
+ 76 more |
|
v1.7.4
patch
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.4
patch
Dependencies (80)
+ 72 more |
|
v1.7.3
patch
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.3
patch
Dependencies (78)
+ 70 more |
|
v1.7.2
patch
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.2
patch
Dependencies (79)
+ 71 more |
|
v1.7.1
minor
1 CVE
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.1
minor
Dependencies (79)
+ 71 more |
|
v1.7.0-rc1
pre
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.7.0-rc1
pre
Dependencies (80)
+ 72 more |
|
v1.6.3
patch
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.6.3
patch
Dependencies (79)
+ 71 more |
|
v1.6.2
patch
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.6.2
patch
Dependencies (79)
+ 71 more |
|
v1.6.1
minor
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.6.1
minor
Dependencies (79)
+ 71 more |
|
v1.15.1
patch
|
v1.15.1
patch
Dependencies (78)
+ 70 more |
|
v1.5.6
patch
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.5.6
patch
Dependencies (74)
+ 66 more |
|
v1.5.5
patch
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.5.5
patch
Dependencies (73)
+ 65 more |
|
v1.5.4
patch
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.5.4
patch
Dependencies (73)
+ 65 more |
|
v1.5.3
patch
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.5.3
patch
Dependencies (73)
+ 65 more |
|
v1.5.2
patch
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.5.2
patch
Dependencies (73)
+ 65 more |
|
v1.5.0
minor
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (73)
+ 65 more |
|
v1.15.0
minor
|
v1.15.0
minor
Dependencies (73)
+ 65 more |
|
v1.4.3
patch
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.4.3
patch
Dependencies (70)
+ 62 more |
|
v1.4.1
patch
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (70)
+ 62 more |
|
v1.4.0
minor
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (70)
+ 62 more |
|
v1.3.1
minor
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.3.1
minor
Dependencies (69)
+ 61 more |
|
v1.3.0-rc1
pre
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.3.0-rc1
pre
Dependencies (68)
+ 60 more |
|
v1.2.2
patch
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (64)
+ 56 more |
|
v1.2.1
patch
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (64)
+ 56 more |
|
v1.2.0
minor
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (64)
+ 56 more |
|
v1.1.0
minor
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (62)
+ 54 more |
|
v1.1.0-rc1
pre
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.1.0-rc1
pre
Dependencies (62)
+ 54 more |
|
v1.0.0
major
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (62)
+ 54 more |
|
v1.0.0-rc3
pre
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.0.0-rc3
pre
Dependencies (62)
+ 54 more |
|
v1.0.0-rc2
pre
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.0.0-rc2
pre
Dependencies (62)
+ 54 more |
|
v1.0.0-rc1
pre
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.0.0-rc1
pre
Dependencies (62)
+ 54 more |
|
v0.17.0
minor
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.17.0
minor
Dependencies (64)
+ 56 more |
|
v0.16.0
minor
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.16.0
minor
Dependencies (58)
+ 50 more |
|
v0.14.0
minor
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.14.0
minor
|
|
v0.13.0
minor
3 CVEs
CVE-2025-32445
GO-2025-3608
GHSA-hmp7-x699-cvhq
Apr 22, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR in github.com/argoproj/argo-events Fixed in
1.9.6
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31054
GO-2022-0490
GHSA-5q86-62xr-3r57
Aug 21, 2024
Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Uses of deprecated API can be used to cause DoS in user-facing endpoints in github.com/argoproj/argo-events Fixed in
1.7.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-25856
GO-2022-0492
GHSA-qpgx-64h2-gc3c
SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-2864522
Jul 15, 2022
Path traversal in github.com/argoproj/argo-events GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem. Fixed in
1.7.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.13.0
minor
|