PatchSiren cyber security CVE debrief
CVE-2026-55797 argoproj CVE debrief
Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL. The vulnerability exists from version 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. Administrators and users managing repositories and credential templates should assess exposure and update to a fixed version to prevent exploitation.
- Vendor
- argoproj
- Product
- argo-cd
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Argo CD administrators and users who manage repositories and credential templates should assess their exposure and take action to update to a fixed version if necessary. GitOps and continuous delivery teams using Argo CD should verify their deployment contexts and restrict access to repository and credential template management to prevent exploitation.
Why it matters
CVE-2026-55797 is a high-severity vulnerability in Argo CD that allows command injection via crafted SSH repository SOCKS5 proxy URLs. Administrators and users managing repositories and credential templates should assess exposure and update to a fixed version to prevent exploitation.
- Potential command injection and execution in the repo-server.
- Access to Git, Helm, and OCI credentials.
- Possible lateral movement within the Kubernetes cluster.
- Required verification of SSH repository proxy URLs and user access controls.
Technical summary
The Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials.
Defensive priority
High
Recommended defensive actions
- Review and update Argo CD to a fixed version (3.3.15, 3.4.10, 3.5.4, or 3.6.0-rc2) if currently using a vulnerable version.
- Restrict access to repository and repository credential template creation and updates to trusted users.
- Monitor repository and credential template changes for suspicious activity.
- Verify SSH repository proxy URLs for suspicious or unknown hosts.
- Perform an inventory of Argo CD deployments to identify potential exposure.
- Review and test compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and source item provide details on the vulnerability in Argo CD. The vulnerability exists from version 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2. The issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-55797 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-55797
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-55797 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55797
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/55xxx/CVE-2026-55797.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-cd/security/advisories/GHSA-j6cw-g6p4-7hch
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-cd/pull/15864
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-cd/commit/1e3ddd0b7250aa23f489956b5fab8c13d0493a9f
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-cd/commit/9b27aeb1a4fb15d11a0f01cad65dea1fdfc60205
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-cd/releases/tag/v3.3.15
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-cd/releases/tag/v3.4.10
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-cd/releases/tag/v3.5.4
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.