Impact
Argo CD’s repo‑server allows an attacker to inject arbitrary shell commands when the system clones or otherwise accesses an SSH Git repository that is configured with a proxy URL. The proxy host and port are inserted into an SSH ProxyCommand string that is executed by a shell without escaping shell metacharacters, enabling the execution of malicious code. The primary impact is remote code execution on the repo‑server, which also gives the attacker access to stored Git, Helm, and OCI credentials.
Affected Systems
Affected products are Argo CD from argoproj:argo-cd. Versions 2.11.0 through the release immediately before 3.3.15, and earlier branches that do not include the fix, are vulnerable. The vulnerability is resolved in Argo CD releases 3.3.15, 3.4.10, 3.5.4, and 3.6.0‑rc2, and all subsequent releases.
Risk and Exploitability
With a CVSS score of 8.8 this vulnerability is rated high severity. The EPSS score is currently unavailable, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector is inferred to be remote: an individual who can create or update a repository or its credential template can supply a crafted proxy host value and thereby achieve arbitrary command execution on the repo‑server. Once compromised, the attacker can read or modify any data the repo‑server accesses, including sensitive credentials stored in the system.
OpenCVE Enrichment
Github GHSA