Command Injection Vulnerability in Argo CD Repository Server
CVE-2026-55797
What is CVE-2026-55797?
Argo CD, a continuous delivery tool for Kubernetes, is susceptible to command injection when handling SSH Git repositories with a proxy URL. This issue arises in versions from 2.11.0 to specific releases in the 3.x series, allowing users with the ability to create or modify repository configurations to inject malicious commands. By supplying a crafted proxy host in the SSH ProxyCommand, an attacker can execute arbitrary commands on the repo-server, thereby gaining unauthorized access to sensitive credentials such as Git, Helm, and OCI. This vulnerability has been addressed in later versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.
Affected Version(s)
argo-cd >= 2.11.0, <= 2.14.21 <= 2.11.0, 2.14.21
argo-cd >= 3.0.0, < 3.3.15 < 3.0.0, 3.3.15
argo-cd >= 3.4.0, < 3.4.10 < 3.4.0, 3.4.10
