Vulnerability Report: GO-2025-3934
- CVE-2025-55190, GHSA-786q-9hcg-v9ff
- Affects: github.com/argoproj/argo-cd, github.com/argoproj/argo-cd/v2, and 1 more
- Published: Sep 08, 2025
Argo CD's Project API Token Exposes Repository Credentials in github.com/argoproj/argo-cd
For detailed information about this vulnerability, visit https://github.com/argoproj/argo-cd/security/advisories/GHSA-786q-9hcg-v9ff or https://nvd.nist.gov/vuln/detail/CVE-2025-55190.
Affected Packages
-
PathVersionsSymbols
Aliases
References
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-786q-9hcg-v9ff
- https://nvd.nist.gov/vuln/detail/CVE-2025-55190
- https://github.com/argoproj/argo-cd/commit/e8f86101f5378662ae6151ce5c3a76e9141900e8
- https://vuln.go.dev/ID/GO-2025-3934.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.