HomeSecuritySecurity flaw in Argo CD Repo-Server allows Kubernetes Clusters to be taken over

Security flaw in Argo CD Repo-Server allows Kubernetes Clusters to be taken over

Argo CD, a widely used tool for software development on Kubernetes, has an unpatched vulnerability in the repo-server component that allows an unauthenticated attacker to execute code if they can gain access to the component's internal network port.

See also: Critical Kubernetes vulnerability allows hackers to execute arbitrary code

Article Image: Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

Synacktiv, which discovered the bug, says it could lead to a full cluster takeover. The company reported the vulnerability to Argo CD maintainers in January 2025, but some eighteen months later, it remains unpatched, prompting Synacktiv to publish the details to warn users.

The flaw is located in repo-server, the component of Argo CD that reads Git repositories and creates Kubernetes manifests. The internal gRPC service lacks authentication, allowing anyone who can access it to send a crafted request to execute a command. Synacktiv demonstrated the attack against Argo CD v2.13.3 and noted that there is no patch available. It did not provide a full list of affected versions.

The technique exploits kustomize, a standard tool used by Argo CD to convert repository files into manifests. Kustomize has a `–helm-command` option that specifies the helm binary to call. Synacktiv found that an unauthenticated request to the repo-server `GenerateManifest` service can set this option to a script, originating from a Git repository controlled by the attacker. When kustomize is run, it executes the script instead of calling helm.

However, “internal” does not imply isolation by default. Argo CD includes Kubernetes network policies that restrict the repo-server’s access to its own components. Synacktiv discovered that the Helm chart, a common method of installing Argo CD, does not enable these policies by default, with `networkPolicy.create` set to false. In this configuration, an attacker who compromises a single pod in the cluster can gain access to the repo-server and exploit the vulnerability.

See also: Vulnerability in Kubernetes allows remote code execution on Windows

Kubernetes

Access to the repo-server allows further actions. Synacktiv used this access to read the cluster's Redis password from an environment variable, connect to Argo CD's Redis cache, and corrupt stored deployment data. During the next automatic synchronization, Argo CD deployed a payload provided by the attacker.

This situation is reminiscent of CVE-2024-31989, a vulnerability discovered by Cycode in 2024, where Argo CD's Redis was passwordless, allowing any pod in the cluster to poison the deployment cache. Although Argo CD addressed this by adding a password to Redis, the cache itself remains unsigned, allowing the same attack to be performed if the password is compromised.

Without a patch available, the recommended defense is network isolation. It is recommended to enable Kubernetes network policies so that only Argo CD components can access the repo-server and Redis ports. Argo CD provides the necessary policy files. However, Helm users must enable them manually, as the chart does not include them by default.

To verify active policies, use the command: `kubectl get networkpolicy -A`. A healthy installation should show one network policy per component, including repo-server and Redis. If these policies are absent, the repo-server and Redis ports may be accessible from the rest of the cluster.

Synacktiv has developed a tool, `argo-cdown`, that automates the full attack. They are currently holding the tool back to give defenders time to secure their network policies, with plans to publish it to GitHub later for administrators to test their own deployments.

This isn't the first time Argo CD has had issues with its internal security. In September 2025, it fixed CVE-2025-55190, where an API token with basic read access could retrieve the credentials of a project's Git repository. In May 2026, another vulnerability, CVE-2026-42880, allowed read-only users to access plaintext Kubernetes secrets.

The pattern is clear: Argo CD aggregates cluster access and repository secrets, and its internal mechanisms continue to expose them, either through unauthenticated requests or low-privilege tokens.

GREYVIBE Russian hacker group cyberattacks Ukraine AI

See also: New attack allows Git Credentials to be exported to ArgoCD

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Until a fix is ​​released, treating the cluster network as hostile remains the only effective defense.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS