Impact
An attacker who can edit a namespace can submit an arbitrary Argo Workflow via the legacy V1 API path of Data Science Pipelines. The API server then creates pods with elevated privileges because the request bypasses the hardened security controls introduced in V2. This produces a confused‑deputy scenario in which the workflow runs with node‑root privileges, allowing the attacker to execute arbitrary code and take full control of the underlying node. The weakness arises from improper permission control (CWE‑266).
Affected Systems
Red Hat AI Inference Server (v3) and Red Hat OpenShift AI. The flaw exists in the V1 API path of Data Science Pipelines used by these products and is applicable to any installation that has not yet applied the vendor’s fix.
Risk and Exploitability
The CVSS score is 7.6, indicating a high impact with potential for full system compromise. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to have namespace editor privileges; once in place, submitting a crafted workflow is straightforward, making the vulnerability highly exploitable within the affected environment.
OpenCVE Enrichment