CVE-2026-55797

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-10: 110-10
Referenced assets1 URL
By indicator
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨HIGH - Argo CD repo-server SSH ProxyCommand OS Command Injection (CVE-2026-55797) Argo CD repo-server builds an ssh ProxyCommand from the repo proxy URL when cloning/testing/fetching SSH Git repos; proxy host/port are shell-interpreted without metacharacter neutralization, enabling command injection by users who can create/update repos or credential templates. Impact: RCE in repo-server context + access to stored Git/Helm/OCI creds. 👉Affected: Argo CD repo-server (http://github.com/argoproj/argo-cd/v2, v3) < 3.3.15 / 3.4.10 / 3.5.4 / 3.6.0-rc2 | Upgrade to 3.3.15 / 3.4.10 / 3.5.4 / 3.6.0-rc2

    0000053
    315 followersView on X

Explore more