An unpatched vulnerability in the Argo CD repo-server component allows unauthenticated attackers to execute arbitrary code and potentially take over Kubernetes clusters. Discovered by Synacktiv and reported to maintainers in January 2025, the flaw remains unfixed after 18 months, prompting public disclosure.
The bug resides in the repo-server’s internal gRPC service, which lacks authentication. Attackers who can reach the service can send crafted requests to abuse kustomize’s –helm-command option, redirecting execution to a malicious script from an attacker-controlled Git repository. Synacktiv demonstrated the attack on Argo CD v2.13.3.
While Argo CD includes Kubernetes network policies to isolate the repo-server, the Helm chart disables them by default (networkPolicy.create set to false). This allows attackers who compromise any pod in the cluster to reach the repo-server and trigger the flaw. Once code execution is achieved, attackers can read the Redis password from environment variables, poison the deployment cache, and deploy malicious workloads during the next automatic sync, effectively reviving CVE-2024-31989.
No patched version is available. Defenders must enable Kubernetes network policies to restrict access to repo-server and Redis ports. Synacktiv plans to release the argo-cdown tool for testing. This is part of a pattern of internal surface exposures in Argo CD, including CVE-2025-55190 and CVE-2026-42880.
CVEs: CVE-2024-31989, CVE-2025-55190, CVE-2026-42880, CVE-2026-20245
Products: Argo CD, Kubernetes, Redis, Helm
Original source: thehackernews.com