{"id":"CVE-2021-37914","aliases":["BIT-argo-workflows-2021-37914","GHSA-h563-xh25-x54q","GO-2022-0928"],"url":"https://o3.security/vulnerability/CVE-2021-37914","summary":"Workflow re-write vulnerability using input parameter","details":"In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflows, an attacker may be able to disrupt a workflow because expression template output is evaluated.","published":"2021-08-03T00:15:08.607Z","modified":"2026-07-09T05:44:43.483378Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/argoproj/argo-workflows/v3","fixedVersion":"3.1.6"}],"fix":{"url":"https://github.com/argoproj/argo-workflows/pull/6442","label":"argoproj/argo-workflows#6442"},"references":[{"type":"REPORT","url":"https://github.com/argoproj/argo-workflows/issues/6441"},{"type":"FIX","url":"https://github.com/argoproj/argo-workflows/pull/6442"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T05:44:43.483378Z"}}