TL;DR
The Argo CD project has fixed four critical security flaws, each rated 9.9 on CVSS. Three of these Argo CD vulnerabilities let a user run commands or read files inside the argocd-repo-server, and the fourth lets Git committers bypass AppProject limits. Patched releases are v3.5.4, v3.4.10, v3.3.15 and v3.6.0-rc2.
- CVE: CVE-2026-77459 R
- CVSS: 9.9 (Critical · CVSSv3)
- Summary: Impact Argo CD checks an Application's AppProject before it creates resources during a sync. That check covers destination namespaces and servers, cluster-scoped resource allow and deny lists, and namespaced resource allow and…
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Too many alerts in your inbox? Switch to one weekly digest, sorted by severity.
Try Team free for 14 daysWhy It Matters
Argo CD is a widely used GitOps tool that deploys apps to Kubernetes clusters from Git. The repo-server holds repository credentials, and the application controller often has broad cluster access. As a result, a flaw in either component can spread far beyond one app.
Several of the bugs need very little access. The advisories note that one upload path “needs only Application get on an existing Application.” The maintainers do not report exploitation in the wild or a public proof-of-concept.
How the Attacks Work
Kustomize Helm Config Home
This flaw applies when operators enable Helm chart rendering in Kustomize. A kustomization can point Helm at a folder inside the repository. Helm then loads and runs a plugin from that folder. Per the advisory, “the command runs as the repo-server user and can read repository credentials and anything else available to that process.”
Kustomize Remote Ref
The second bug abuses how Kustomize fetches remote bases. It passes a version value to Git without separating it from command-line options. A crafted value can make Git run a command inside the repo-server. Notably, the maintainers warn that “blocking repo-server egress does not prevent this,” because the trigger never leaves the pod.
Jsonnet File Read
Argo CD evaluates Jsonnet files with an importer that can open any path the repo-server can read. A malicious file can pull in the process environment, service-account tokens, private keys and repository credentials. Argo CD redacts generated Secrets, yet the stolen data can still come back to the caller through a ConfigMap. It can also read from a device file until the process runs out of memory.
AppProject Bypass (CVE-2026-77459)
AppProjects limit where and what an application can deploy. However, PreDelete and PostDelete hooks skipped that check. A user who can push to the backing Git repo can commit a hook the project would normally refuse. When someone deletes the app, Argo CD creates that hook with the controller’s credentials. In a typical install, that could mean a cluster-wide role binding. Other hook types, such as PreSync and PostSync, still pass through the project check.
Affected Versions
Each of the four Argo CD vulnerabilities reaches back years:
- Kustomize Helm config home: v2.1.0 and later
- Kustomize remote ref: v2.7.0 and later
- Jsonnet file read: v0.9.0 and later
- AppProject hook bypass (CVE-2026-77459): v2.10.0 and later
Every currently supported release is affected. Argo CD 2.x and 3.0 through 3.2 are out of support and will not get a patch.
Patch and Mitigation Steps
Upgrade to v3.5.4, v3.4.10, v3.3.15 or v3.6.0-rc2. Full details sit in the four GitHub advisories, GHSA-fmxq-cgp8-87wp, GHSA-m3vr-7329-44ww, GHSA-9v9p-x54c-58gc and GHSA-fw5c-w8rc-j7fx.
If you cannot upgrade right away, the advisories list partial workarounds:
- Remove –enable-helm from the Kustomize build options to close the Helm flaw.
- Set jsonnet.enable to “false” in the argocd-cm ConfigMap to skip Jsonnet files.
- Pin Kustomize to a version older than 5.0, such as 4.5.7, for the remote ref bug.
- Limit who can push to Git repos and who can delete Applications.
Each workaround breaks some features, and the remote ref advisory states that “there is no complete workaround besides upgrading.” Restricting Application get access only closes the upload route, not the Git route. Patching remains the only full fix for these Argo CD vulnerabilities.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!