Declarative Continuous Deployment for Kubernetes
github.com/argoproj/argo-cd/v2 has critical vulnerabilities — do not use
Update to >= 3.2.0-rc2 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| critical | BIT-argo-cd-2025-47933 | Argo CD allows cross-site scripting on repositories page | 3.0.4 |
| critical | BIT-argo-cd-2025-55190 | Argo CD's Project API Token Exposes Repository Credentials | 3.1.2 |
| high | CVE-2023-40025 | Argo CD web terminal session doesn't expire | 2.0.0-20230821201509-e047efa8f951 |
| unknown | BIT-argo-cd-2025-47933 | Argo CD allows cross-site scripting on repositories page in github.com/argoproj/argo-cd | 3.0.4 |
| unknown | BIT-argo-cd-2025-59531 | Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd | 3.2.0-rc2 |
| unknown | BIT-argo-cd-2025-59537 | argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload in github.com/argoproj/argo-cd | 3.2.0-rc2 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/github.com/argoproj/argo-cd/v2Last updated · 2025-11-04T14:56:45Z