Argo CD 3.5.4, 3.4.10 and 3.3.15 Fix Eight Advisories, Four Rated Critical at CVSS 9.9, Including Repo-Server Command Execution and File Reads
The Argo CD project released patched versions on October 6, 2026 covering eight security advisories; GitHub lists four as Critical with a 9.9 CVSS score. Older minor lines get no patch.
Editor's Note ·
- Clarification:
- The article says the advisories for the AppProject, SSH proxy, login and OCI issues each state that Argo CD 2.x and 3.0 through 3.2 are out of support. The advisories word this differently: the AppProject and SSH advisories (and the extension-proxy advisory, not named in the article) say 2.x and 3.0 through 3.2; the login advisory says 1.x, 2.x and 3.0 through 3.2; the OCI advisory says only 3.1 and 3.2 are affected and out of support.
Overview
The Argo CD project, the Kubernetes continuous-delivery tool, shipped four releases on October 6, 2026 that carry the same set of security fixes. The v3.5.4 release notes list eight issues, four of them labeled CRITICAL; the release page carries a 20:55 UTC timestamp. The same list appears in v3.4.10, v3.3.15 and the pre-release v3.6.0-rc2. The project’s individual GitHub advisories, which show a publication date of October 7, 2026, give each of the four critical issues a CVSS score of 9.9.
All figures and affected-version statements below come from the Argo CD project’s own release notes and advisories as read on October 10, 2026. No independent outlet was consulted, and none of the pages reviewed reports exploitation in the wild.
The four critical issues
Three of the four involve the repo-server, the component that renders manifests from Git repositories.
- Kustomize remote ref (GHSA-9v9p-x54c-58gc). Per the advisory, Kustomize passes a remote URL’s ref or version value to git fetch without a
--separator, so a value starting with a dash can be parsed as a Git option. The advisory says--upload-packcan then run a command inside argocd-repo-server when the remote is a local transport such asfile://. It lists all versions from v2.7.0 onward as affected. It says the payload can be supplied either through a Git-committed Kustomization or through an API upload route that needs only Applicationgetpermission, and states that there is no complete workaround besides upgrading. - Kustomize Helm config home (GHSA-fw5c-w8rc-j7fx). The advisory describes a kustomization that points Helm at a repository-controlled directory and runs a downloader plugin from it inside the repo-server. It lists versions from v2.1.0 onward as affected and says deployments that do not pass
--enable-helmtokustomize buildare not affected. Not passing that flag inkustomize.buildOptionsis described as a complete workaround, though applications that render Helm charts through Kustomize cannot use it. - Jsonnet import (GHSA-m3vr-7329-44ww). The advisory says Argo CD evaluates
.jsonnetfiles in the repo-server with an importer that can open any path the process can read, and that the exposed data can include the process environment, the projected service-account token, mounted private keys and repository credentials. It lists versions from v0.9.0 onward as affected. Settingjsonnet.enableto"false"in theargocd-cmConfigMap is given as a workaround; the advisory notes that Jsonnet-only directories then sync without those manifests. - AppProject bypass by delete hooks (GHSA-fmxq-cgp8-87wp). The release notes list this one with CVE-2026-77459. The advisory says PreDelete and PostDelete hooks skip the AppProject check that sync applies, so a user who can push to the backing Git repository could have a hook created with the application-controller’s credentials when the Application is deleted. It lists versions from v2.10.0 onward as affected.
The other four
The release notes rate two issues HIGH and two MODERATE. The advisory scores are as shown by GitHub on October 10, 2026.
- GHSA-j6cw-g6p4-7hch (CVE-2026-55797), High, 8.8: command injection through a repository proxy URL on SSH Git repositories, affecting v2.11.0 onward. The advisory says the repository must use SSH.
- GHSA-4439-h7jw-5cjj (CVE-2025-61560, as listed in the release notes), High, 7.5: the login failure limit, which the advisory says defaults to 5 failures in a 5-minute window, can be exceeded by concurrent requests. It lists v1.5.3 onward as affected.
- GHSA-w996-f2wq-x9c6, Moderate, 6.5: an oversized OCI manifest can exhaust repo-server memory, affecting v3.1.0 onward.
- GHSA-g3ff-q88g-chrj, Moderate, 4.9: extension-proxy RBAC ignores the application namespace. The advisory says it applies only when proxy extensions and applications in any namespace are both enabled.
What operators need to do
According to the advisories, patched versions are v3.6.0-rc2, v3.5.4, v3.4.10 and v3.3.15. The advisories for the AppProject, SSH proxy, login and OCI issues state that Argo CD 2.x and 3.0 through 3.2 are out of support and will not receive a patch, and tell users to move to a patched 3.3 or newer release.
The v3.5.4 release notes flag two potentially breaking changes. Kustomize builds that render Helm charts no longer honor helmGlobals.configHome; ordinary http, https and oci chart repositories still work, but builds that depended on a Helm plugin registered from that directory will not. Separately, an OCI manifest larger than 4 MiB is now rejected.
What we don’t know
- The pages reviewed do not say whether any of the issues has been exploited. The project’s advisories describe impact and preconditions, not observed attacks.
- The release notes list CVE identifiers for only three of the eight issues (CVE-2026-77459, CVE-2025-61560 and CVE-2026-55797); the other five are identified only by GHSA numbers on the pages reviewed.
- Scores and affected-version ranges come from the project’s own advisories. No independent severity assessment was reviewed for this article.