github.com/argoproj/argo-cd/v2 vulnerabilities
CVEs whose affected-version data names the github.com/argoproj/argo-cd/v2 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
16 CVEsRSS
CVE-2025-47933Critical· 9.0Argo CD allows cross-site scripting on repositories page
Argo CD allows cross-site scripting on repositories page
CVE-2025-23216Medium· 6.8Argo CD does not scrub secret values from patch errors
Argo CD does not scrub secret values from patch errors
CVE-2024-41666Medium· 4.7The Argo CD web terminal session does not handle the revocation of user permissions properly
The Argo CD web terminal session does not handle the revocation of user permissions properly
CVE-2024-32476Medium· 6.5Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
CVE-2024-31990Medium· 4.8Argo CD's API server does not enforce project sourceNamespaces
Argo CD's API server does not enforce project sourceNamespaces
CVE-2024-29893Medium· 6.5ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
CVE-2024-21661High· 7.5Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
CVE-2024-21652Medium· 5.4Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
CVE-2024-28175Critical· 9.0Cross-site scripting on application summary component
Cross-site scripting on application summary component
CVE-2023-50726Medium· 6.4Users with `create` but not `override` privileges can perform local sync
Users with `create` but not `override` privileges can perform local sync
CVE-2024-22424High· 8.3github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
CVE-2023-40026Medium· 5.0Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
CVE-2022-41354Medium· 5.3Argo CD authenticated but unauthorized users may enumerate Application names via the API
Argo CD authenticated but unauthorized users may enumerate Application names via the API
CVE-2023-22736High· 8.5Controller reconciles apps outside configured namespaces when sharding is enabled
Controller reconciles apps outside configured namespaces when sharding is enabled
CVE-2022-24348High· 7.7PoCPath traversal and dereference of symlinks in Argo CD
Path traversal and dereference of symlinks in Argo CD
CVE-2021-23347Medium· 4.7Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2