github.com/argoproj/argo-cd vulnerabilities
CVEs whose affected-version data names the github.com/argoproj/argo-cd package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
12 CVEsRSS
CVE-2025-47933Critical· 9.0Argo CD allows cross-site scripting on repositories page
Argo CD allows cross-site scripting on repositories page
CVE-2025-23216Medium· 6.8Argo CD does not scrub secret values from patch errors
Argo CD does not scrub secret values from patch errors
CVE-2024-36106Medium· 4.3Argo-cd authenticated users can enumerate clusters by name
Argo-cd authenticated users can enumerate clusters by name
CVE-2024-21661High· 7.5Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
CVE-2024-28175Critical· 9.0Cross-site scripting on application summary component
Cross-site scripting on application summary component
CVE-2023-50726Medium· 6.4Users with `create` but not `override` privileges can perform local sync
Users with `create` but not `override` privileges can perform local sync
CVE-2024-22424High· 8.3github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
CVE-2023-40026Medium· 5.0Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
CVE-2022-41354Medium· 5.3Argo CD authenticated but unauthorized users may enumerate Application names via the API
Argo CD authenticated but unauthorized users may enumerate Application names via the API
CVE-2023-23947Critical· 9.1Users with any cluster secret update access may update out-of-bounds cluster secrets
Users with any cluster secret update access may update out-of-bounds cluster secrets
CVE-2022-1025Critical· 9.9Improper access control allows admin privilege escalation in Argo CD
Improper access control allows admin privilege escalation in Argo CD
CVE-2022-24348High· 7.7PoCPath traversal and dereference of symlinks in Argo CD
Path traversal and dereference of symlinks in Argo CD