Skip to main content

Execution with Unnecessary Privileges

CVE-2025-32445

Severity High
Score 9.9/10

Summary

A user with permission to create/modify "EventSource" and "Sensor" custom resources can gain privileged access to the host system and cluster, even without having direct administrative privileges. This issue affects github.com/argoproj/argo-events versions prior to 1.9.6.

  • LOW
  • NETWORK
  • HIGH
  • CHANGED
  • NONE
  • LOW
  • HIGH
  • HIGH

CWE-250 - Execution with Unnecessary Privileges

The software performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Advisory Timeline

  • Published