github.com/argoproj/argo-cd/v3 vulnerabilities
CVEs whose affected-version data names the github.com/argoproj/argo-cd/v3 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-42880Critical· 9.6PoCArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
▾ Abyssalargoproj · github.com/argoproj/argo-cd/v3EPSS 0.51%via OSV
CVE-2025-47933Critical· 9.0Argo CD allows cross-site scripting on repositories page
Argo CD allows cross-site scripting on repositories page
▾ Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.46%via OSV