GHSA-2hj5-g64g-fp6p · Severity: critical · Ecosystem: go — Argo CD allows cross-site scripting on repositories page
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository. This issue has been patched in versions 2.13.8, 2.14.13, and 3.0.4.
Conclusion & alert: CVE-2025-47933 is rated Moderate Risk (43.3/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.07%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-25 | 0.01% | 0.07% | +0.06% |
| 2 | 2025-11-21 | 0.07% | 0.01% | -0.06% |
| 3 | 2025-11-18 | — | 0.07% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.0 | 3.1 | CRITICAL |
|
2.3 | 6.0 | [email protected] |
| 5.4 | 3.1 | MEDIUM |
|
2.3 | 2.7 | [email protected] |
GHSA-2hj5-g64g-fp6p · Severity: critical · Ecosystem: go — Argo CD allows cross-site scripting on repositories page
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-47933 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2025-47933/ |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| argoproj | argo_cd | >= 1.2.1, < 2.13.8 | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* |
| argoproj | argo_cd | >= 2.14.0, < 2.14.13 | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* |
| argoproj | argo_cd | >= 3.0.0, < 3.0.4 | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* |
| argoproj | argo_cd | 1.2.0 | cpe:2.3:a:argoproj:argo_cd:1.2.0:rc1:*:*:*:*:*:* |
| argoproj | argo_cd | 1.2.0 | cpe:2.3:a:argoproj:argo_cd:1.2.0:rc2:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/argoproj/argo-cd/commit/a5b4041a79c54bc7b3d090805d070bcdb9a9e4d1 | Patch |
| https://github.com/argoproj/argo-cd/security/advisories/GHSA-2hj5-g64g-fp6p | Patch Third Party Advisory |