Argo CD, Command Injection, CVE-2026-55797 (High) -DC-Oct2026-3021

Listen to this Post

  1. CVE-2026-55797 is a high-severity command injection vulnerability affecting the Argo CD repo-server.
  2. It stems from how Argo CD processes SOCKS5, HTTP, and HTTPS proxy configurations for SSH Git repositories.
  3. Specifically, when a repository is configured with a proxy URL, the proxy host and port parameters are passed directly.
  4. These parameters are copied into an underlying SSH ProxyCommand execution routine without proper sanitization.
  5. An attacker who has permissions to create or update a repository or credential template can supply malicious payloads.
  6. If the supplied proxy host string contains shell metacharacters, it breaks out of the intended ProxyCommand context.
  7. This allows arbitrary shell commands to be executed directly inside the running repo-server container environment.
  8. The vulnerability affects all versions of Argo CD starting from v2.11.0, including all supported releases up to v3.x.
  9. Older versions like v2.10.20 and earlier are completely unaffected because SOCKS5 proxy support was introduced later.
  10. The vulnerable code path was originally introduced via commit 9b27aeb1a4 on January 9, 2024, under pull request 15864.
  11. Only repositories utilizing the SSH protocol trigger this vulnerable command construction behavior during cloning or fetching.
  12. HTTPS Git repositories using an HTTP proxy utilize a different code path and do not build this specific proxy command.
  13. Any user or entity capable of creating or updating a repository object can successfully inject the malicious proxy string.
  14. This includes project-scoped repository permissions, executing the argocd repo add command with a proxy flag, or creating a Secret.
  15. Furthermore, credential templates inherit and apply their configured proxy settings to every matching SSH repository without explicit credentials.
  16. Argo CD automatically triggers the execution of this vulnerable command during initial connection tests and subsequent fetches.
  17. Because the repo-server process stores or handles various credentials, successful execution exposes sensitive information.
  18. It can read other stored Git credentials, Helm repository tokens, and OCI registry secrets accessible to the repo-server.
  19. Furthermore, since the repo-server processes repository data, an attacker can leverage this execution to poison cached data.
  20. Poisoned cache entries can then propagate malicious Kubernetes manifests downstream into managed clusters during synchronization cycles.
  21. This turns an application-layer vulnerability into a potential full-scale compromise of downstream managed Kubernetes environments.
  22. Unauthenticated network access to the repo-server gRPC interface or Redis database can drastically accelerate the attack chain.
  23. If network policies are misconfigured or left disabled—such as in default Helm installations—internal pods can reach the server.
  24. Consequently, lateral movement from a compromised cluster workload directly to the repo-server becomes entirely feasible.
  25. Mitigating this flaw requires immediate attention, including upgrading affected instances to patched versions or applying network isolation.
  26. Official patches have been released by the maintainers in versions v3.6.0-rc2, v3.5.4, v3.4.10, and v3.3.15 respectively.
  27. Instances running unsupported major versions like 2.x or 3.0 through 3.2 must be upgraded immediately to secure releases.
  28. Reviewing existing repository definitions and credential template secrets for anomalous proxy values is also essential.
  29. Restricting network access using strict Kubernetes NetworkPolicies remains a critical defense-in-depth measure against exploitation.
  30. Understanding these technical mechanics helps security teams detect anomalous child processes and safeguard their GitOps pipelines.

DailyCVE Form:

Platform: Argo CD
Version: v2.11.0 onward
Vulnerability: Command Injection
Severity: High Risk
date: October 2026

Prediction: Patches Released Now

What Undercode Say:

Bash Commands and Codes

Add repository with malicious proxy string for testing/reproduction
argocd repo add [email protected]:example/repo.git --proxy socks5://127.0.0.1:1080/;id;
Check running repo-server child processes for anomalous shells
kubectl exec -n argocd deployment/argocd-repo-server -- ps aux
Apply fixed Argo CD manifest version
kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.4/manifests/install.yaml

Exploit: (Educational Purposes!)

An attacker creates or updates an SSH Git repository configuration (via `argocd repo add –proxy` or a Kubernetes Secret) specifying a proxy URL containing shell metacharacters, such as socks5://legitimate-proxy:1080/;$(id > /tmp/pwned). When Argo CD repo-server processes the repository clone or connection test, it builds an SSH `ProxyCommand` string embedding this proxy host value directly into a shell execution context without adequate sanitization. The embedded shell commands break out of the intended proxy argument bounds and execute with the privileges of the `argocd-repo-server` process, allowing command execution and access to stored credentials.

Protection

Upgrade Argo CD immediately to a patched version such as v3.5.4, v3.4.10, v3.3.15, or v3.6.0-rc2. For older unsupported versions (2.x and 3.0-3.2), upgrade to a supported and patched release stream. Review existing repository secrets and credential templates to identify and remove any unexpected or unauthorized proxy values. Enforce strict Kubernetes NetworkPolicies within the `argocd` namespace to restrict ingress to the repo-server and prevent unauthorized pods from reaching internal gRPC endpoints.

Impact

Successful exploitation allows remote code execution within the Argo CD repo-server container. The malicious process can read stored Git credentials, Helm registry tokens, and OCI secrets. Furthermore, attackers can manipulate cached data or push malicious Kubernetes manifests downstream into managed clusters during regular sync operations, potentially resulting in full tenant or cluster-wide compromise.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top