A critical vulnerability has been discovered in Argo CD, which allows API tokens with limited privileges to gain access to sensitive repository credentials. The issue is located in the API endpoint , which exposes usernames and passwords, undermining the platform, providing access to secrets without explicit permissions.
See also: A2: New AI tool for discovering & validating Android vulnerabilities

The vulnerability results from an improper authorization check in the Project API, specifically at the /api/v1/projects/{project}/detailed endpoint. According to the vulnerability details, API tokens with typical project-level permissions, such as those for managing applications, can retrieve all repository credentials associated with that project.
The expected behavior is that any request for sensitive information, such as secrets, would require explicit, elevated permissions. However, the actual behavior allows tokens with basic access to retrieve this data.
This issue is not limited to roles specific to Argo CD. Any token that holds project recovery rights is considered vulnerable, including those with broader, global rights. This significantly expands the potential attack surface, as more general-purpose tokens could be used to exploit the vulnerability.
See also: CISA warns of Android vulnerability exploitation

The exploit is simple. An attacker in possession of a valid API token with the necessary permissions can make a simple authenticated call to the project's detailed API endpoint. The resulting JSON response will incorrectly include a repositories object containing plaintext username and password credentials for the repositories associated with the project. This allows an attacker to easily harvest credentials that can be used to access private source code repositories.
The consequences of this vulnerability are serious, as exposed credentials could lead to source code theft, malicious code injection into the CI/CD pipeline, and further compromise of the development infrastructure.
The Argo CD development team has addressed the issue and released corrective updates. Administrators are strongly advised to upgrade their installations to one of the following secure releases immediately to mitigate the risk.
- v3.1.2
- v3.0.14
- v2.14.16
- v2.13.9
See also: Hackers exploit critical vulnerability in SAP S/4HANA

Upgrading to a fixed version will ensure that the API endpoint correctly enforces permission checks and prevents unauthorized disclosure of repository credentials.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
