argoproj has 33 CVEs on record between 2021 and 2026. Cadence is steady at roughly 5 per quarter. The busiest recent month was May 2026 with 3. The median CVSS is 7.3 (high), with 6 rated critical. None have a confirmed exploitation report. Most affected products: github.com/argoproj/argo-cd (10), github.com/argoproj/argo-cd/v2 (9), github.com/argoproj/argo-workflows/v4 (3).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 5 prev 4
Products
- github.com/argoproj/argo-cd 10
- github.com/argoproj/argo-cd/v2 9
- github.com/argoproj/argo-workflows/v4 3
- argo_cd 2
- github.com/argoproj/argo-workflows/v3 2
- argo-rollouts 1
33
Total CVEs
6
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-42880Critical· 9.6ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction65CVE-2022-1025Critical· 9.9Improper access control allows admin privilege escalation in Argo CD55CVE-2022-24348High· 7.7Path traversal and dereference of symlinks in Argo CD55CVE-2026-82277Critical· 9.8Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection54CVE-2025-47933Critical· 9.0Argo CD allows cross-site scripting on repositories page50
argoproj vulnerabilities
CVEs affecting argoproj, newest first. Open any entry for full detail, references, and exploit status.
33 CVEsRSS
CVE-2022-1025Critical· 9.9Improper access control allows admin privilege escalation in Argo CD
Improper access control allows admin privilege escalation in Argo CD
▾ Midnightargoproj · github.com/argoproj/argo-cdEPSS 1.3%via OSV
CVE-2022-24348High· 7.7PoCPath traversal and dereference of symlinks in Argo CD
Path traversal and dereference of symlinks in Argo CD
▾ Midnightargoproj · github.com/argoproj/argo-cd/v2EPSS 2.7%via OSV
CVE-2021-23347Medium· 4.7Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2
Possible XSS when using SSO with the CLI in github.com/argoproj/argo-cd/v2
▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.59%via OSV