Answer in brief
CVE-2026-55797 records a High severity (CVSS 8.8) vulnerability in Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL. The current sources do not mark it as known exploited. The current feed maps argoproj/argo-cd (generic), github.com/argoproj/argo-cd/v2 (go), github.com/argoproj/argo-cd/v2 (go), github.com/argoproj/argo-cd/v3 (go) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps argoproj/argo-cd (generic), github.com/argoproj/argo-cd/v2 (go), github.com/argoproj/argo-cd/v2 (go), github.com/argoproj/argo-cd/v3 (go) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| argoproj/argo-cdgeneric | >=2.11.0 <=2.14.21 || >=3.0.0 <3.3.15 || >=3.4.0 <3.4.10 || >=3.5.0 <3.5.4 || = 3.6.0-rc1 | 3.3.15, 3.4.10, 3.5.4 |
| github.com/argoproj/argo-cd/v2go | >=2.11.0,<=2.14.21 | Not reported |
| github.com/argoproj/argo-cd/v2go | >=2.11.0 | Not reported |
| github.com/argoproj/argo-cd/v3go | >=3.0.0,<3.3.15 | 3.3.15 |
| github.com/argoproj/argo-cd/v3go | >=3.4.0,<3.4.10 | 3.4.10 |
| github.com/argoproj/argo-cd/v3go | >=3.5.0,<3.5.4 | 3.5.4 |
| github.com/argoproj/argo-cd/v3go | =3.6.0-rc1 | 3.6.0-rc2 |
| github.com/argoproj/argo-cd/v3go | >=3.0.0 <3.3.15 | 3.3.15 |
| github.com/argoproj/argo-cd/v3go | >=3.4.0 <3.4.10 | 3.4.10 |
| github.com/argoproj/argo-cd/v3go | >=3.5.0 <3.5.4 | 3.5.4 |
| github.com/argoproj/argo-cd/v3go | >=3.6.0-rc1 <3.6.0-rc2 | 3.6.0-rc2 |
Published upstream
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 9, 2026
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.
Quoted source text, attributed separately from HOL analysis.