vulnerability
Published 2026-10-09
Verified 2026-10-10

Argo CD CVE-2026-55797 (CVSS 8.8): a crafted proxy URL on an SSH Git repository injects shell commands into the repo-server, exposing every stored Git, Helm and OCI credential; fixed in 3.3.15, 3.4.10, 3.5.4 and 3.6.0-rc2, no patch for 2.x or 3.0–3.2

The Argo CD project published advisory GHSA-j6cw-g6p4-7hch on 9 October 2026 for a command injection in the repo-server, the component of the Kubernetes GitOps tool that clones and renders application repositories. When an SSH Git repository has a proxy URL set, Argo CD copies the proxy host and port into an SSH ProxyCommand that runs through a shell without escaping, so a host value containing shell metacharacters runs attacker commands inside the repo-server. The command fires when the repository connection is tested and on every later fetch, and the repo-server process can read the other Git, Helm and OCI credentials it holds. Anyone allowed to create or update a repository or a repository credential template can set the proxy, including users with only project-scoped repository permissions, the argocd repo add --proxy flag, or a repository Secret; a credential template pushes its proxy to every matching SSH repository without its own credentials. HTTPS repositories using an HTTP proxy are not affected. The bug arrived with SOCKS5 proxy support for SSH URLs in v2.11.0 (January 2024 change), so every supported release was exposed. The fix stops passing the proxy through a shell. Argo CD 2.x and 3.0 to 3.2 are out of support and will not be patched. No exploitation reported. Primary: Argo CD GitHub security advisory.

Product
Argo CD (argoproj/argo-cd) GitOps continuous delivery for Kubernetes — repo-server
Versions
2.11.0 to 2.14.x (no fix), 3.0 to 3.2 (no fix), 3.3 before 3.3.15, 3.4 before 3.4.10, 3.5 before 3.5.4, 3.6.0-rc1
CVSS
(CVSS 3.1, GitHub advisory)
Exploited in Australia?
unknown
Patch to
Upgrade to Argo CD 3.3.15, 3.4.10, 3.5.4 or 3.6.0-rc2 or later; 2.x and 3.0–3.2 must move to a patched 3.3+ release. Until then, remove proxy settings from SSH repositories and from credential templates that match SSH URLs, restrict repository create/update (including project-scoped repository rights) to trusted admins, review repository and credential-template Secrets for unexpected proxy values, and rotate repo-server Git, Helm and OCI credentials if a strange proxy turns up.

Primary: Argo CD GHSA-j6cw-g6p4-7hch — repo-server command injection via crafted SSH repository proxy URL (CVE-2026-55797, 9 Oct 2026) · Vendor: Argo CD fix commit — proxy host and port no longer passed through a shell · CVE: CVE-2026-55797 · GitHub Advisory Database — GHSA-j6cw-g6p4-7hch

tech cloud identity