Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository. This issue has been patched in versions 2.13.8, 2.14.13, and 3.0.4.
Metrics
Affected Vendors & Products
References
History
Fri, 30 May 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 29 May 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in Argo CD, where improper filtering of repository URLs in the UI allows JavaScript injection. A crafted javascript: link can lead to cross-site scripting when viewed by another user. This can result in unauthorized API actions via the victim's session. | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository. This issue has been patched in versions 2.13.8, 2.14.13, and 3.0.4. |
Title | argocd: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) | Argo CD allows cross-site scripting on repositories page |
References |
| |
Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 29 May 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in Argo CD, where improper filtering of repository URLs in the UI allows JavaScript injection. A crafted javascript: link can lead to cross-site scripting when viewed by another user. This can result in unauthorized API actions via the victim's session. | |
Title | argocd: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) | |
First Time appeared |
Redhat
Redhat openshift Gitops |
|
Weaknesses | CWE-79 | |
CPEs | cpe:/a:redhat:openshift_gitops:1.14::el8 cpe:/a:redhat:openshift_gitops:1.15::el8 cpe:/a:redhat:openshift_gitops:1.16::el8 cpe:/a:redhat:openshift_gitops:1.16::el9 |
|
Vendors & Products |
Redhat
Redhat openshift Gitops |
|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-29T19:30:39.108Z
Updated: 2025-05-30T12:35:04.233Z
Reserved: 2025-05-14T10:32:43.529Z
Link: CVE-2025-47933

Updated: 2025-05-30T12:35:00.369Z

Status : Awaiting Analysis
Published: 2025-05-29T20:15:27.473
Modified: 2025-05-30T16:31:03.107
Link: CVE-2025-47933
