GHSA-274v-mgcv-cm8jMedium· 6.8▾ SunlitArgo CD GitOps Engine does not scrub secret values from patch errors
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository.
The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data.
A patch for this vulnerability is available in the following Argo CD versions:
There is no workaround other than upgrading.
Fixed with commit https://github.com/argoproj/argo-cd/commit/6f5537bdf15ddbaa0f27a1a678632ff0743e4107 & https://github.com/argoproj/gitops-engine/commit/7e21b91e9d0f64104c8a661f3f390c5e6d73ddca
github.com/argoproj/gitops-engine >= 0.7.2, <= 0.7.3github.com/argoproj/gitops-engine < 0.7.1-0.20250129155113-4c6e03c463141Upgrade to a patched release:
github.com/argoproj/gitops-engine 0.7.1-0.20250129155113-4c6e03c463141Connected by shared product, vendor, weakness, or advisory.
CVE-2025-23216Medium· 6.8Argo CD does not scrub secret values from patch errors
CVE-2024-37152Medium· 5.3Unauthenticated Access to sensitive settings in Argo CD
CVE-2024-21661High· 7.5Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
CVE-2023-22736High· 8.5Controller reconciles apps outside configured namespaces when sharding is enabled
CVE-2023-40026Medium· 5.0Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
CVE-2026-40886High· 7.7Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller