github.com/argoproj/argo-cd

govv1.8.6

Declarative Continuous Deployment for Kubernetes

License Apache-2.0permissive143 versions1981 maintainers0 deps22,706 weekly dl
argoproj/argo-cd
30
/ 100
Health
do not use

github.com/argoproj/argo-cd has critical vulnerabilities — do not use

Update to >= 3.2.0-rc2 to fix known vulnerabilities

  • Low health score (30/100)
  • 10 high severity vulnerabilities
  • 7 critical vulnerabilities
Health breakdown0 – 100
0/25
maintenance
10/20
popularity
0/25
security
15/15
maturity
5/15
community
Vulnerabilities
47
7 critical10 high10 medium20 low
Advisories (47)
SeverityIDSummaryFixed in
criticalCVE-2022-24768Improper access control allows admin privilege escalation in Argo CD2.3.2
criticalBIT-argo-cd-2025-47933Argo CD allows cross-site scripting on repositories page3.0.4
highCVE-2022-31034Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params2.4.1
mediumCVE-2022-41354Argo CD authenticated but unauthorized users may enumerate Application names via the API2.4.28
mediumBIT-argo-cd-2024-36106Argo-cd authenticated users can enumerate clusters by name2.11.3
mediumBIT-argo-cd-2025-23216Argo CD does not scrub secret values from patch errors2.11.13
highCVE-2022-24348Path traversal and dereference of symlinks in Argo CD2.1.9
mediumCVE-2023-40026Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server2.3.0
highBIT-argo-cd-2024-21661Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment2.10.4
mediumGO-2022-0387Helm OCI credentials leaked into Argo CD logs1.8.7
highCVE-2022-31105Argo CD certificate verification is skipped for connections to OIDC providers2.4.5
highCVE-2024-22424github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability2.10-rc2
highCVE-2022-1025Argo CD improper access control bug can allow malicious user to escalate privileges to admin level2.3.2
criticalBIT-argo-cd-2024-31989ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache2.11.1
highBIT-argo-cd-2025-59531Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload3.0.19
mediumBIT-argo-cd-2023-50726Users with `create` but not `override` privileges can perform local sync2.8.12
criticalCVE-2022-31035Argo CD's external URLs for Deployments can include JavaScript2.4.1
mediumCVE-2022-24731Path traversal allows leaking out-of-bound files from Argo CD repo-server2.3.0
mediumCVE-2022-31016DoS through large manifest files in Argo CD2.4.1
highBIT-argo-cd-2024-40634Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint2.11.6
... and 27 more

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/github.com/argoproj/argo-cd

Last updated · 2021-02-26T21:12:06Z

github.com/argoproj/argo-cd — Health Score 30/100 | DepScope