CVE-2026-55797 | Argo Project Argo CD up to 3.6.0-rc1 repo-server command injection

SecurityVulns

A vulnerability was found in Argo Project Argo CD up to 2.14.21/3.3.14/3.4.9/3.5.3/3.6.0-rc1 and classified as very critical. The impacted element is an unknown function of the component repo-server. Executing a manipulation can lead to command injection.

This vulnerability is tracked as CVE-2026-55797. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More