Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j6cw-g6p4-7hch | Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL |
Fri, 09 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2. | |
| Title | Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T17:53:53.357Z
Reserved: 2026-06-17T14:40:28.381Z
Link: CVE-2026-55797
No data.
Status : Awaiting Analysis
Published: 2026-10-09T17:16:47.710
Modified: 2026-10-09T17:41:15.270
Link: CVE-2026-55797
No data.
OpenCVE Enrichment
No data.
Github GHSA