Vendor
An attacker with namespace editor privileges can bypass security hardening via the V1 API to execute malicious Argo Workflows, resulting in node-root access.