Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j6cw-g6p4-7hch | Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL |
Fri, 09 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj
Argoproj argo-cd |
|
| Vendors & Products |
Argoproj
Argoproj argo-cd |
Fri, 09 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2. | |
| Title | Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T17:53:53.357Z
Reserved: 2026-06-17T14:40:28.381Z
Link: CVE-2026-55797
Updated: 2026-10-09T17:53:50.417Z
Status : Awaiting Analysis
Published: 2026-10-09T17:16:47.710
Modified: 2026-10-09T18:17:08.530
Link: CVE-2026-55797
No data.
OpenCVE Enrichment
Updated: 2026-10-09T18:30:11Z
Github GHSA