| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j6cw-g6p4-7hch | Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 09 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj
Argoproj argo-cd |
|
| Vendors & Products |
Argoproj
Argoproj argo-cd |
Fri, 09 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2. | |
| Title | Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T17:53:53.357Z
Reserved: 2026-06-17T14:40:28.381Z
Link: CVE-2026-55797
Updated: 2026-10-09T17:53:50.417Z
Status : Awaiting Analysis
Published: 2026-10-09T17:16:47.710
Modified: 2026-10-09T18:17:08.530
Link: CVE-2026-55797
No data.
OpenCVE Enrichment
Updated: 2026-10-09T18:45:10Z
Github GHSA