CVE-2025-47933 Details
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository. This issue has been patched in versions 2.13.8, 2.14.13, and 3.0.4.
A cross-site scripting vulnerability has been identified in Argo CD, a GitOps continuous delivery tool for Kubernetes, prior to versions 2.13.8, 2.14.13, and 3.0.4. The issue arises from improper filtering of URL protocols on the repository page, allowing an attacker to inject malicious scripts that could be executed with permission to edit the repository. This exploitation could enable the attacker to perform arbitrary actions on behalf of the victim via the API, such as creating, modifying, or deleting Kubernetes resources.
Users can update to Argo CD versions 2.13.8, 2.14.13, or 3.0.4, where this vulnerability has been patched. The patch includes improved validation of repository URLs to prevent the injection of malicious scripts.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/argoproj/argo-cd/commit/a5b4041a79c54bc7b3d090805d070bcdb9a9e4d1 | [email protected] | Patch |
| https://github.com/argoproj/argo-cd/security/advisories/GHSA-2hj5-g64g-fp6p | [email protected] | PatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| argoproj argo cd | >= 1.2.1, < 2.13.8 >= 2.14.0, < 2.14.13 >= 3.0.0, < 3.0.4 1.2.0 rc1 1.2.0 rc2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 27, 2025 | Initial Analysis | [email protected] |
| May 29, 2025 | New CVE Received | [email protected] |