CRITICAL🇵🇱 Wersja polska

CVE-2025-47933

CVSS 9.0v3.1pub. 2025-05-29upd. 2025-08-27

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository. This issue has been patched in versions 2.13.8, 2.14.13, and 3.0.4.

🤖 AI Analysis
How it works

The vulnerability results from improper filtering of URL protocols on the repository page in Argo CD. An attacker with repository editing permissions can inject a malicious XSS payload. When the victim visits the appropriate page, the payload executes in their browser and allows the attacker to send requests to the Argo CD API in the context of the victim's session. This enables the attacker to take control of actions performed by the victim in the application.

Impact

An attacker can perform arbitrary actions through the Argo CD API on behalf of a logged-in victim, potentially gaining access to sensitive configuration data, modifying Kubernetes resources, or escalating privileges in the GitOps environment.

Mitigation & patch

Argo CD should be updated to version 2.13.8, 2.14.13, or 3.0.4, in which the vulnerability has been fixed. Additionally, it is recommended to restrict repository editing permissions exclusively to trusted users.

Who is affected

Argo CD in versions earlier than 2.13.8, 2.14.13, and 3.0.4

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Argoproj Argo Cd

    APP
    Argoproj
    1.2.01.2.1 – 2.13.8 (excl.)2.14.0 – 2.14.13 (excl.)3.0.0 – 3.0.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSSContainer
CWE
References

Related vulnerabilities

CVE-2026-42880CRITICAL9.6PL ✓same product

Argo CD: ujawnienie danych Secret Kubernetes przez endpoint ServerSideDiff

CVE-2025-55190CRITICAL9.9PL ✓same product

Argo CD: nieuprawniony dostęp do poświadczeń repozytoriów przez API token

CVE-2024-31989CRITICAL9.0PL ✓same product

Argo CD: nieautoryzowany dostęp do Redis umożliwia privilege escalation

CVE-2024-21652CRITICAL9.8PL ✓same product

Argo CD: Ominięcie ochrony przed brute force logowania

CVE-2024-28175CRITICAL9.0PL ✓same product

Argo CD: XSS w adnotacjach linków umożliwia przejęcie uprawnień