PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-55797 argoproj CVE debrief

Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL. The vulnerability exists from version 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. Administrators and users managing repositories and credential templates should assess exposure and update to a fixed version to prevent exploitation.

Vendor
argoproj
Product
argo-cd
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Argo CD administrators and users who manage repositories and credential templates should assess their exposure and take action to update to a fixed version if necessary. GitOps and continuous delivery teams using Argo CD should verify their deployment contexts and restrict access to repository and credential template management to prevent exploitation.

Why it matters

CVE-2026-55797 is a high-severity vulnerability in Argo CD that allows command injection via crafted SSH repository SOCKS5 proxy URLs. Administrators and users managing repositories and credential templates should assess exposure and update to a fixed version to prevent exploitation.

  • Potential command injection and execution in the repo-server.
  • Access to Git, Helm, and OCI credentials.
  • Possible lateral movement within the Kubernetes cluster.
  • Required verification of SSH repository proxy URLs and user access controls.

Technical summary

The Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials.

Defensive priority

High

Recommended defensive actions

  • Review and update Argo CD to a fixed version (3.3.15, 3.4.10, 3.5.4, or 3.6.0-rc2) if currently using a vulnerable version.
  • Restrict access to repository and repository credential template creation and updates to trusted users.
  • Monitor repository and credential template changes for suspicious activity.
  • Verify SSH repository proxy URLs for suspicious or unknown hosts.
  • Perform an inventory of Argo CD deployments to identify potential exposure.
  • Review and test compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and source item provide details on the vulnerability in Argo CD. The vulnerability exists from version 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2. The issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-55797 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-55797

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-55797 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55797

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/55xxx/CVE-2026-55797.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/argoproj/argo-cd/security/advisories/GHSA-j6cw-g6p4-7hch

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/argoproj/argo-cd/pull/15864

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/argoproj/argo-cd/commit/1e3ddd0b7250aa23f489956b5fab8c13d0493a9f

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/argoproj/argo-cd/commit/9b27aeb1a4fb15d11a0f01cad65dea1fdfc60205

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/argoproj/argo-cd/releases/tag/v3.3.15

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/argoproj/argo-cd/releases/tag/v3.4.10

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/argoproj/argo-cd/releases/tag/v3.5.4

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.