VendorsArgoprojargo_cdany version
Vulnerabilities

Argoproj Argo Project Argo CD any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

55CVEs
CVE-2021-3557
A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.
Published 2022-02-16 · Modified
6.5EPSS 0.008
CVE-2024-41666
The Argo CD web terminal session does not handle the revocation of user permissions properly.
Published 2024-07-24 · Analyzed
6.5EPSS 0.007
CVE-2026-45737
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
Published 2026-07-15 · Analyzed
6.5EPSS 0.005
CVE-2025-55191
Repository Credentials Race Condition Crashes Argo CD Server
Published 2025-09-30 · Analyzed
6.5EPSS 0.005
CVE-2023-50726
Users with `create` but not `override` privileges can perform local sync in argo-cd
Published 2024-03-13 · Analyzed
6.4EPSS 0.005
CVE-2024-31990
Argo CD' API server does not enforce project sourceNamespaces
Published 2024-04-15 · Analyzed
6.3EPSS 0.004
CVE-2021-26924
An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not activated due to the missing XSS protection header.
Published 2021-03-15 · Modified
6.1EPSS 0.007
CVE-2022-31102
Cross-site Scripting for Argo CD single sign on users
Published 2022-07-12 · Modified
6.1EPSS 0.006
CVE-2021-23135
Argo CD leaked secret data into error messages and logs on invalid edits via UI
Published 2021-05-12 · Modified
5.9EPSS 0.002
CVE-2023-40026
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
Published 2023-09-27 · Modified
5.0EPSS 0.005
CVE-2021-23347
Cross-site Scripting (XSS)
Published 2021-03-03 · Modified
4.8EPSS 0.006
CVE-2022-24905
Argo CD login screen allows message spoofing if SSO is enabled
Published 2022-05-20 · Modified
4.3EPSS 0.013
CVE-2022-24904
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server
Published 2022-05-20 · Modified
4.3EPSS 0.011
CVE-2022-31036
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server
Published 2022-06-27 · Modified
4.3EPSS 0.009
CVE-2024-36106
Argo CD allows authenticated users to enumerate clusters by name
Published 2024-06-06 · Modified
4.3EPSS 0.004
← Prev2 / 2