CVE-2025-55190 is a critical vulnerability in Argo CD versions 2.13.0-2.13.8, 2.14.0-2.14.15, 3.0.0-3.0.12, and 3.1.0-rc1-3.1.1, allowing API tokens with project-level or even just project "get" permissions to retrieve sensitive repository credentials. This vulnerability carries a CVSS score of 9.9 (CRITICAL), indicating a network-based attack with low complexity, no user interaction, and high impact on confidentiality, integrity, and availability. While not yet listed in KEV or having public Metasploit/ExploitDB modules, Nuclei templates exist, and the vulnerability has garnered significant community discussion and media coverage, suggesting a high likelihood of future exploitation. Organizations using affected Argo CD versions should upgrade immediately to 2.13.9, 2.14.16, 3.0.14, or 3.1.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, < 2.13.9CPE matchmatch criteria | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | ||
>= 2.14.0, < 2.14.16CPE matchmatch criteria | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.14CPE matchmatch criteria | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | ||
>= 3.1.0, < 3.1.2CPE matchmatch criteria | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.