Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.

Project Subscriptions

Vendors Products
Argoproj Subscribe
Argo-cd Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j6cw-g6p4-7hch Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 09 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Argoproj
Argoproj argo-cd
Vendors & Products Argoproj
Argoproj argo-cd

Fri, 09 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.
Title Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T17:53:53.357Z

Reserved: 2026-06-17T14:40:28.381Z

Link: CVE-2026-55797

cve-icon Vulnrichment

Updated: 2026-10-09T17:53:50.417Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T17:16:47.710

Modified: 2026-10-09T18:17:08.530

Link: CVE-2026-55797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T18:45:10Z

Weaknesses