Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.
Published: 2026-10-09
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Command Injection
Action: Patch
AI Analysis

Impact

Argo CD’s repo‑server allows an attacker to inject arbitrary shell commands when the system clones or otherwise accesses an SSH Git repository that is configured with a proxy URL. The proxy host and port are inserted into an SSH ProxyCommand string that is executed by a shell without escaping shell metacharacters, enabling the execution of malicious code. The primary impact is remote code execution on the repo‑server, which also gives the attacker access to stored Git, Helm, and OCI credentials.

Affected Systems

Affected products are Argo CD from argoproj:argo-cd. Versions 2.11.0 through the release immediately before 3.3.15, and earlier branches that do not include the fix, are vulnerable. The vulnerability is resolved in Argo CD releases 3.3.15, 3.4.10, 3.5.4, and 3.6.0‑rc2, and all subsequent releases.

Risk and Exploitability

With a CVSS score of 8.8 this vulnerability is rated high severity. The EPSS score is currently unavailable, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector is inferred to be remote: an individual who can create or update a repository or its credential template can supply a crafted proxy host value and thereby achieve arbitrary command execution on the repo‑server. Once compromised, the attacker can read or modify any data the repo‑server accesses, including sensitive credentials stored in the system.

Generated by OpenCVE AI on October 9, 2026 at 18:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Argo CD to a fixed release such as v3.3.15, v3.4.10, v3.5.4, v3.6.0‑rc2, or newer.
  • Temporarily remove or block any SSH proxy configuration from repository or credential definitions until the upgrade is applied.
  • Enforce strict validation of proxy URL values to disallow shell metacharacters and consider switching to non‑SSH clone methods if proxy usage is unavoidable.

Generated by OpenCVE AI on October 9, 2026 at 18:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j6cw-g6p4-7hch Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL
History

Fri, 09 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Argoproj
Argoproj argo-cd
Vendors & Products Argoproj
Argoproj argo-cd

Fri, 09 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.
Title Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Argoproj Argo-cd
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T17:53:53.357Z

Reserved: 2026-06-17T14:40:28.381Z

Link: CVE-2026-55797

cve-icon Vulnrichment

Updated: 2026-10-09T17:53:50.417Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T17:16:47.710

Modified: 2026-10-09T18:17:08.530

Link: CVE-2026-55797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T18:30:11Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')