---
id: CVE-2025-55190
title: >-
  github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials
  (CVE-2025-55190)
summary: >-
  An information leak was discovered in how Argo CD handles API tokens. The
  project details API endpoint could provide unintentional access to sensitive
  repository credentials.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-522
vendor: Red Hat
product: Red Hat OpenShift GitOps 1.17
affected:
  - openshift_gitops
  - openshift_gitops 1.15
  - openshift_gitops 1.16
  - openshift_gitops 1.17
  - openshift_gitops 1.18
  - openshift_gitops 1.19
patched:
  - openshift_gitops 1.15
  - openshift_gitops 1.16
  - openshift_gitops 1.17
  - openshift_gitops 1.18
  - openshift_gitops 1.19
published: '2025-09-04'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T15:57:25+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55190.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55190.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-55190'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2390026'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-55190'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-55190'
  - url: >-
      https://github.com/argoproj/argo-cd/security/advisories/GHSA-786q-9hcg-v9ff
  - url: 'https://access.redhat.com/errata/RHSA-2025:15387'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15388'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15389'
  - url: 'https://access.redhat.com/errata/RHSA-2026:1018'
  - url: 'https://access.redhat.com/errata/RHSA-2026:1017'
  - url: 'https://access.redhat.com/errata/RHSA-2026:1488'
  - url: >-
      https://github.com/argoproj/argo-cd/commit/e8f86101f5378662ae6151ce5c3a76e9141900e8
  - url: 'https://github.com/argoproj/argo-cd'
tags:
  - csaf
  - vex
  - red-hat
  - exploit-available
  - osv
  - go
epss: 0.05463
epssPercentile: 0.9245
exploits:
  nuclei:
    - CVE-2025-55190
  checkedAt: '2026-09-26T09:05:34.024Z'
exploitAvailable: true
aliases:
  - GHSA-786q-9hcg-v9ff
  - BIT-argo-cd-2025-55190
  - GO-2025-3934
ecosystem: go
scores:
  vendor: 8.8
  osv: 9.9
ingestedAt: '2026-09-12T03:13:01.763Z'
---

## Overview

An information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.

## Vendor advisories

- **RHSA-2025:15387** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.15 · released 2025-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:15387)
- **RHSA-2025:15388** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.16 · released 2025-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:15388)
- **RHSA-2025:15389** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.17 · released 2025-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:15389)
- **RHSA-2026:1018** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.17 · released 2026-01-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:1018)
- **RHSA-2026:1017** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.18 · released 2026-01-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:1017)
- **RHSA-2026:1488** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.19 · released 2026-01-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:1488)
- **Red Hat VEX** · Important · affected: Red Hat OpenShift GitOps · no fix planned: Red Hat OpenShift GitOps · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55190.json)

**github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials** — rated Important by Red Hat. Released 2025-09-04, updated 2026-09-21.

Affected:

- Red Hat OpenShift GitOps

Fixed:

- Red Hat OpenShift GitOps 1.15
- Red Hat OpenShift GitOps 1.16
- Red Hat OpenShift GitOps 1.17
- Red Hat OpenShift GitOps 1.18
- Red Hat OpenShift GitOps 1.19

No fix planned:

- Red Hat OpenShift GitOps

Not affected:

- Red Hat OpenShift GitOps 1.15
- Red Hat OpenShift GitOps 1.16
- Red Hat OpenShift GitOps 1.17
- Red Hat OpenShift GitOps 1.18
- Red Hat OpenShift GitOps 1.19
- Red Hat Developer Hub
- Red Hat OpenShift GitOps

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15387
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15388
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15389

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2025-55190)

Affected packages:

- `github.com/argoproj/argo-cd/v2 >= 2.13.0, < 2.13.9`
- `github.com/argoproj/argo-cd/v2 >= 2.14.0, < 2.14.16`
- `github.com/argoproj/argo-cd/v3 < 3.0.14`
- `github.com/argoproj/argo-cd/v3 >= 3.1.0-rc1, < 3.1.2`

Patched in:

- `github.com/argoproj/argo-cd/v2 2.13.9`
- `github.com/argoproj/argo-cd/v2 2.14.16`
- `github.com/argoproj/argo-cd/v3 3.0.14`
- `github.com/argoproj/argo-cd/v3 3.1.2`

Source: https://osv.dev/vulnerability/GHSA-786q-9hcg-v9ff
