GHSA-6wxg-hpw6-m2x7HighCVSS 7.6

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges...

Published
August 10, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.

🔗 References (7)