PT-2026-108985 · Argo Cd · Argo Cd

CVE-2026-55797

·

Published

2026-10-09

·

Updated

2026-10-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Argo CD versions 2.11.0 through 3.3.14 Argo CD versions 3.4.0 through 3.4.9 Argo CD versions 3.5.0 through 3.5.3 Argo CD versions 3.6.0-rc1 and earlier
Description The Argo CD repo-server is subject to command injection when cloning, testing, or fetching an SSH Git repository configured with a proxy URL. The issue occurs because the proxy host and port are embedded into an SSH ProxyCommand and executed through a shell without neutralizing shell metacharacters. An attacker with permissions to create or update a repository or repository credential template can provide a crafted proxy host to execute arbitrary commands in the repo-server. This may allow the attacker to access Git, Helm, and OCI credentials stored within the server. This behavior affects SSH repositories using http, https, or socks5 proxy URLs.
Recommendations Update to version 3.3.15. Update to version 3.4.10. Update to version 3.5.4. Update to version 3.6.0-rc2. Do not grant repository create or update permissions to untrusted users, including project-scoped repository access. Avoid setting a proxy on SSH repositories or on credential templates that match SSH repositories. Review existing repository and credential-template Secrets for unexpected proxy values.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55797
GHSA-J6CW-G6P4-7HCH

Affected Products

Argo Cd