PT-2026-108985 · Argo Cd · Argo Cd
CVE-2026-55797
·
Published
2026-10-09
·
Updated
2026-10-10
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Argo CD versions 2.11.0 through 3.3.14
Argo CD versions 3.4.0 through 3.4.9
Argo CD versions 3.5.0 through 3.5.3
Argo CD versions 3.6.0-rc1 and earlier
Description
The Argo CD repo-server is subject to command injection when cloning, testing, or fetching an SSH Git repository configured with a proxy URL. The issue occurs because the proxy host and port are embedded into an SSH
ProxyCommand and executed through a shell without neutralizing shell metacharacters. An attacker with permissions to create or update a repository or repository credential template can provide a crafted proxy host to execute arbitrary commands in the repo-server. This may allow the attacker to access Git, Helm, and OCI credentials stored within the server. This behavior affects SSH repositories using http, https, or socks5 proxy URLs.Recommendations
Update to version 3.3.15.
Update to version 3.4.10.
Update to version 3.5.4.
Update to version 3.6.0-rc2.
Do not grant repository create or update permissions to untrusted users, including project-scoped repository access.
Avoid setting a proxy on SSH repositories or on credential templates that match SSH repositories.
Review existing repository and credential-template Secrets for unexpected
proxy values.Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Argo Cd