Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-55190

51
FAUCET Score

CVE-2025-55190 is a critical vulnerability in Argo CD versions 2.13.0-2.13.8, 2.14.0-2.14.15, 3.0.0-3.0.12, and 3.1.0-rc1-3.1.1, allowing API tokens with project-level or even just project "get" permissions to retrieve sensitive repository credentials. This vulnerability carries a CVSS score of 9.9 (CRITICAL), indicating a network-based attack with low complexity, no user interaction, and high impact on confidentiality, integrity, and availability. While not yet listed in KEV or having public Metasploit/ExploitDB modules, Nuclei templates exist, and the vulnerability has garnered significant community discussion and media coverage, suggesting a high likelihood of future exploitation. Organizations using affected Argo CD versions should upgrade immediately to 2.13.9, 2.14.16, 3.0.14, or 3.1.2.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.2.0, < 2.13.9CPE matchmatch criteria
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
>= 2.14.0, < 2.14.16CPE matchmatch criteria
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.0.14CPE matchmatch criteria
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
>= 3.1.0, < 3.1.2CPE matchmatch criteria
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.52%
Probability of exploitation in next 30 days
EPSS Percentile
90.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2025-55190 · Sep 18, 2025
This CVE's current EPSS score of 0.0452 is in the 91st percentile among its peer group of 1,124 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/argoproj/argo-cd/v2Fixed in: 2.13.9
gopatch availablevia ghsa
Product: github.com/argoproj/argo-cd/v2Fixed in: 2.14.16
gopatch availablevia ghsa
Product: github.com/argoproj/argo-cd/v3Fixed in: 3.0.14
gopatch availablevia ghsa
Product: github.com/argoproj/argo-cd/v3Fixed in: 3.1.2
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift GitOps 1.15Fixed in: openshift-gitops-1/gitops-operator-bundle:sha256:0b1771f697a700263c5b827dbde56a5c9bab610e9d7df55ef93885a4e54cc0e9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift GitOps 1.15Fixed in: openshift-gitops-1/gitops-rhel8-operator:sha256:0f704cdcda6d7055c8190423ef2082d7147e01559462926496e1060469104183
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift GitOps 1.16Fixed in: openshift-gitops-1/gitops-operator-bundle:sha256:8441322a0fce02df407573675b5b5d92d56de97c8aec72541b33d2dadc4050d5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift GitOps 1.16Fixed in: openshift-gitops-1/gitops-rhel8-operator:sha256:9b7b062ea6abd5c95ff00f7cb5ff1e1fd51b459601eed7118a1d95fc79337629
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift GitOps 1.17Fixed in: openshift-gitops-1/gitops-operator-bundle:sha256:be93be0341649215fb001725aac0c3c5925343adbf1ad00c979b8c3d489512d6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift GitOps 1.17Fixed in: openshift-gitops-1/gitops-rhel8-operator:sha256:12722a8a7feacff1852d8c309256522bd217f5c34c78871b5debbaa5e576eed9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift GitOps 1.17Fixed in: openshift-gitops-1/gitops-rhel8:sha256:d12e12f7aa0f40272033174000422448695ccaa5f5331624144be0506e3f2475
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift GitOps 1.18Fixed in: openshift-gitops-1/gitops-rhel8:sha256:853107e7329e189ded3fc5ca657366e27010f468b1be813264efd9e2cf90c906
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift GitOps 1.19Fixed in: openshift-gitops-1/gitops-rhel8:sha256:e7bffd143cb74ca3c5271a7b6db5c0350f06c09ec4ca5975f16a6a4e22938a6f
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-agent-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel9

Vendor Advisories (2)

goGHSA-786q-9hcg-v9ffcritical

Argo CD's Project API Token Exposes Repository Credentials

Sep 4, 2025
redhatCVE-2025-55190Important

github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials

Sep 4, 2025

References

github.com / argoproj/argo-cd/commit/e8f86101f5378662ae6151ce5c3a76e9141900e8
Patch
github.com / argoproj/argo-cd/security/advisories/GHSA-786q-9hcg-v9ff
ExploitVendor Advisory