{"id":"CVE-2025-55190","title":"github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials (CVE-2025-55190)","summary":"An information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-522","vendor":"Red Hat","product":"Red Hat OpenShift GitOps 1.17","affected":["openshift_gitops","openshift_gitops 1.15","openshift_gitops 1.16","openshift_gitops 1.17","openshift_gitops 1.18","openshift_gitops 1.19"],"patched":["openshift_gitops 1.15","openshift_gitops 1.16","openshift_gitops 1.17","openshift_gitops 1.18","openshift_gitops 1.19"],"published":"2025-09-04","updated":"2026-09-21","sourceUpdated":"2026-09-21T15:57:25+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55190.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55190.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-55190"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2390026"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-55190"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55190"},{"url":"https://github.com/argoproj/argo-cd/security/advisories/GHSA-786q-9hcg-v9ff"},{"url":"https://access.redhat.com/errata/RHSA-2025:15387"},{"url":"https://access.redhat.com/errata/RHSA-2025:15388"},{"url":"https://access.redhat.com/errata/RHSA-2025:15389"},{"url":"https://access.redhat.com/errata/RHSA-2026:1018"},{"url":"https://access.redhat.com/errata/RHSA-2026:1017"},{"url":"https://access.redhat.com/errata/RHSA-2026:1488"},{"url":"https://github.com/argoproj/argo-cd/commit/e8f86101f5378662ae6151ce5c3a76e9141900e8"},{"url":"https://github.com/argoproj/argo-cd"}],"tags":["csaf","vex","red-hat","exploit-available","osv","go"],"epss":0.0534,"epssPercentile":0.92308,"exploits":{"nuclei":["CVE-2025-55190"],"checkedAt":"2026-09-21T16:44:46.137Z"},"exploitAvailable":true,"aliases":["GHSA-786q-9hcg-v9ff","BIT-argo-cd-2025-55190","GO-2025-3934"],"ecosystem":"go","scores":{"vendor":8.8,"osv":9.9},"ingestedAt":"2026-09-12T03:13:01.763Z","slug":"CVE-2025-55190","body":"## Overview\n\nAn information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.\n\n## Vendor advisories\n\n- **RHSA-2025:15387** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.15 · released 2025-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:15387)\n- **RHSA-2025:15388** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.16 · released 2025-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:15388)\n- **RHSA-2025:15389** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.17 · released 2025-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:15389)\n- **RHSA-2026:1018** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.17 · released 2026-01-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:1018)\n- **RHSA-2026:1017** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.18 · released 2026-01-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:1017)\n- **RHSA-2026:1488** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.19 · released 2026-01-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:1488)\n- **Red Hat VEX** · Important · affected: Red Hat OpenShift GitOps · no fix planned: Red Hat OpenShift GitOps · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55190.json)\n\n**github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials** — rated Important by Red Hat. Released 2025-09-04, updated 2026-09-21.\n\nAffected:\n\n- Red Hat OpenShift GitOps\n\nFixed:\n\n- Red Hat OpenShift GitOps 1.15\n- Red Hat OpenShift GitOps 1.16\n- Red Hat OpenShift GitOps 1.17\n- Red Hat OpenShift GitOps 1.18\n- Red Hat OpenShift GitOps 1.19\n\nNo fix planned:\n\n- Red Hat OpenShift GitOps\n\nNot affected:\n\n- Red Hat OpenShift GitOps 1.15\n- Red Hat OpenShift GitOps 1.16\n- Red Hat OpenShift GitOps 1.17\n- Red Hat OpenShift GitOps 1.18\n- Red Hat OpenShift GitOps 1.19\n- Red Hat Developer Hub\n- Red Hat OpenShift GitOps\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\nFor details on how to apply this update, refer to:\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15387\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\nFor details on how to apply this update, refer to:\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15388\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\nFor details on how to apply this update, refer to:\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15389\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2025-55190)\n\nAffected packages:\n\n- `github.com/argoproj/argo-cd/v2 >= 2.13.0, < 2.13.9`\n- `github.com/argoproj/argo-cd/v2 >= 2.14.0, < 2.14.16`\n- `github.com/argoproj/argo-cd/v3 < 3.0.14`\n- `github.com/argoproj/argo-cd/v3 >= 3.1.0-rc1, < 3.1.2`\n\nPatched in:\n\n- `github.com/argoproj/argo-cd/v2 2.13.9`\n- `github.com/argoproj/argo-cd/v2 2.14.16`\n- `github.com/argoproj/argo-cd/v3 3.0.14`\n- `github.com/argoproj/argo-cd/v3 3.1.2`\n\nSource: https://osv.dev/vulnerability/GHSA-786q-9hcg-v9ff","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":1.1,"exploitation":12,"ransomware":0},"changes":[{"seq":208569,"id":"CVE-2025-55190","ts":1790009104788,"field":"cvss","old":"9.9","new":"8.8"},{"seq":208568,"id":"CVE-2025-55190","ts":1790009104788,"field":"severity","old":"critical","new":"high"}]}