{"id":"CVE-2026-55797","summary":"Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL","details":"Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.","aliases":["GHSA-j6cw-g6p4-7hch"],"modified":"2026-10-10T02:47:24.426999711Z","published":"2026-10-09T16:43:35.954Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.3.15"},{"introduced":"3.4.0"},{"fixed":"3.4.10"},{"introduced":"3.5.0"},{"fixed":"3.5.4"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55797.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55797.json"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/1e3ddd0b7250aa23f489956b5fab8c13d0493a9f"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/9b27aeb1a4fb15d11a0f01cad65dea1fdfc60205"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/pull/15864"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v3.3.15"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v3.4.10"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v3.5.4"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v3.6.0-rc2"},{"type":"ADVISORY","url":"https://github.com/argoproj/argo-cd/security/advisories/GHSA-j6cw-g6p4-7hch"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55797"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/argoproj/argo-cd","events":[{"introduced":"d3f33c00197e7f1d16f2a73ce1aeced464b07175"},{"last_affected":"206a6eeca509bbf7f239301f3d3fa498c23251a4"},{"introduced":"b7e3f52c2827c5c9e0dd41d71b292bbeb66010be"},{"last_affected":"b7e3f52c2827c5c9e0dd41d71b292bbeb66010be"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"2.11.0"},{"last_affected":"2.14.21"},{"introduced":"= 3.6.0-rc1"},{"last_affected":"= 3.6.0-rc1"}]}}],"versions":["= 3.6.0-rc1","v3.6.0-rc1","gitops-engine/v3.6.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55797.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}