GHSA-786q-9hcg-v9ff · Severity: critical · Ecosystem: go — Argo CD's Project API Token Exposes Repository Credentials
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets. This vulnerability does not only affect project-level permissions. Any token with project get permissions is also vulnerable, including global permissions such as: `p, role/user, projects, get, *, allow`. This issue is fixed in versions 2.13.9, 2.14.16, 3.0.14 and 3.1.2.
Conclusion & alert: CVE-2025-55190 is rated High Exploit Risk (87.5/100): CVSS Critical severity, with high exploitation likelihood (EPSS 5.38%, 90th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.34% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-21 | 4.03% | 5.38% | +1.34% |
| 2 | 2026-03-18 | 7.12% | 4.03% | -3.09% |
| 3 | 2026-03-02 | — | 7.12% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.9 | 3.1 | CRITICAL |
|
3.1 | 6.0 | [email protected] |
GHSA-786q-9hcg-v9ff · Severity: critical · Ecosystem: go — Argo CD's Project API Token Exposes Repository Credentials
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-55190 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| argoproj | argo_cd | >= 2.2.0, < 2.13.9 | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* |
| argoproj | argo_cd | >= 2.14.0, < 2.14.16 | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* |
| argoproj | argo_cd | >= 3.0.0, < 3.0.14 | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* |
| argoproj | argo_cd | >= 3.1.0, < 3.1.2 | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/argoproj/argo-cd/commit/e8f86101f5378662ae6151ce5c3a76e9141900e8 | Patch |
| https://github.com/argoproj/argo-cd/security/advisories/GHSA-786q-9hcg-v9ff | Exploit Vendor Advisory |