CVE-2025-55190 Details
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets. This vulnerability does not only affect project-level permissions. Any token with project get permissions is also vulnerable, including global permissions such as: `p, role/user, projects, get, *, allow`. This issue is fixed in versions 2.13.9, 2.14.16, 3.0.14 and 3.1.2.
A vulnerability exists in Argo CD versions 2.13.0 prior to 2.13.9, 2.14.0 prior to 2.14.16, 3.0.0 prior to 3.0.14, and 3.1.0-rc1 prior to 3.1.2. API tokens with project-level permissions can access sensitive repository credentials, including usernames and passwords, through the project details API endpoint. This occurs even when the token only has standard application management permissions and no explicit access to secrets. The vulnerability also affects any token with project get permissions, including certain global permissions.
Users can upgrade to Argo CD versions 2.13.9, 2.14.16, 3.0.14, or 3.1.2 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| argoproj argo cd | >= 2.2.0, < 2.13.9 >= 2.14.0, < 2.14.16 >= 3.0.0, < 3.0.14 >= 3.1.0, < 3.1.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 19, 2025 | Initial Analysis | [email protected] |
| Sep 4, 2025 | New CVE Received | [email protected] |