S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Nov 4, 2025

CVE-2025-55190 Scanner

CVE-2025-55190 Scanner - Information Disclosure vulnerability in ArgoCD

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-55190
9.9
CVSScritical
Exploitable remotely over the internet · low-privilege account sufficient.

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets. This vulnerability does not only affect project-level permissions. Any token with project get permissions is also vulnerable, including global permissions such as: `p, role/user, projects, get, *, allow`. This issue is fixed in versions 2.13.9, 2.14.16, 3.0.14 and 3.1.2.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
argo-cdby argoproj
>= 2.13.0, < 2.13.9
Updated Aug 22, 2026View on NVD →
Detail

This scanner tests for vulnerabilities in ArgoCD, a popular open-source tool for deploying and managing applications on Kubernetes. ArgoCD is widely used by operations teams and developers to enable continuous delivery and GitOps workflows in cloud and on-premises environments. It provides secure and automated deployment management, making it essential for managing application lifecycles. With its role in streamlining operations, ensuring the security of ArgoCD is crucial to avoid potential disruptions in application delivery pipelines. ArgoCD is integrated with various platforms, making its security vital for maintaining the integrity of widely used applications. Identifying vulnerabilities in ArgoCD helps safeguard its role in efficient and reliable software delivery.

The vulnerability detected by this scanner is an Information Disclosure issue in ArgoCD. It allows API tokens with project-level permissions to access sensitive credentials through the project details API. This happens even if the user does not have explicit permissions to access this data, posing a serious security risk. The vulnerability affects several versions, including all with v2.2.0-rc1 and later. It enables unauthorized users to obtain sensitive repository credentials. Identifying this vulnerability is crucial to prevent unauthorized access and potential data breaches.

Technically, this vulnerability is located in the ArgoCD API endpoints. The vulnerable endpoint is '/api/v1/projects/default/detailed', which can be accessed with the 'GET' method. When a legitimate user logs in using their credentials, the API token obtained can be exploited to make unauthorized requests. The vulnerable parameter involves using the extracted token in requests, allowing access to sensitive data. This scanner checks for the presence of repositories and associated credentials in the response. If the condition is met, it confirms the presence of an Information Disclosure vulnerability.

Exploitation of this vulnerability can lead to severe consequences, such as unauthorized access to sensitive information stored in repositories, including usernames and passwords. Malicious actors can leverage these credentials to perform unauthorized actions on the system. It can potentially lead to further exploits in connected systems, data breaches, and compromise of application integrity. It also poses reputational and legal risks for organizations, necessitating immediate attention and mitigation.

REFERENCES

Solution Advice
  • Update to the latest secure version of ArgoCD that addresses this vulnerability.
  • Restrict API token permissions and regularly audit token usage to minimize exposure risks.
  • Implement strict access control measures and monitor for suspicious activities.
  • Ensure robust logging and alerting mechanisms are in place to detect unauthorized access attempts.
  • Conduct regular security assessments and vulnerability scans to identify and remediate similar issues.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.