argoproj Vulnerabilities and Affected Products
Vulnerabilities associated with argo_cd.
Products
Clear product- argo-cd44 vulnerabilities
- argo-workflows16 vulnerabilities
- argo-helm4 vulnerabilities
- argo-events2 vulnerabilities
- argo_cd2 vulnerabilities
- Argo CD1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-55190CRITICAL | Argo CD: Project API Token Exposes Repository CredentialsArgo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets. This vulnerability does not only affect project-… | CVSS10.0v3.1 | EPSS4.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-28175CRITICAL | Cross-site scripting on application summary component in argo-cdArgo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of links specified in the `link.argocd.argoproj.io` annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the s… CWE-79Mar 13, 2024 | CVSS9.1v3.1 | EPSS0.654% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |