
🚨HIGH - Argo CD repo-server SSH ProxyCommand OS Command Injection (CVE-2026-55797) Argo CD repo-server builds an ssh ProxyCommand from the repo proxy URL when cloning/testing/fetching SSH Git repos; proxy host/port are shell-interpreted without metacharacter neutralization, enabling command injection by users who can create/update repos or credential templates. Impact: RCE in repo-server context + access to stored Git/Helm/OCI creds. 👉Affected: Argo CD repo-server (http://github.com/argoproj/argo-cd/v2, v3) < 3.3.15 / 3.4.10 / 3.5.4 / 3.6.0-rc2 | Upgrade to 3.3.15 / 3.4.10 / 3.5.4 / 3.6.0-rc2
