Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository. This issue has been patched in versions 2.13.8, 2.14.13, and 3.0.4.
History

Fri, 30 May 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 29 May 2025 19:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Argo CD, where improper filtering of repository URLs in the UI allows JavaScript injection. A crafted javascript: link can lead to cross-site scripting when viewed by another user. This can result in unauthorized API actions via the victim's session. Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository. This issue has been patched in versions 2.13.8, 2.14.13, and 3.0.4.
Title argocd: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) Argo CD allows cross-site scripting on repositories page
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:L'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Thu, 29 May 2025 02:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Argo CD, where improper filtering of repository URLs in the UI allows JavaScript injection. A crafted javascript: link can lead to cross-site scripting when viewed by another user. This can result in unauthorized API actions via the victim's session.
Title argocd: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS)
First Time appeared Redhat
Redhat openshift Gitops
Weaknesses CWE-79
CPEs cpe:/a:redhat:openshift_gitops:1.14::el8
cpe:/a:redhat:openshift_gitops:1.15::el8
cpe:/a:redhat:openshift_gitops:1.16::el8
cpe:/a:redhat:openshift_gitops:1.16::el9
Vendors & Products Redhat
Redhat openshift Gitops
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:L'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-29T19:30:39.108Z

Updated: 2025-05-30T12:35:04.233Z

Reserved: 2025-05-14T10:32:43.529Z

Link: CVE-2025-47933

cve-icon Vulnrichment

Updated: 2025-05-30T12:35:00.369Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-29T20:15:27.473

Modified: 2025-05-30T16:31:03.107

Link: CVE-2025-47933

cve-icon Redhat

Severity : Important

Publid Date: 2025-05-28T14:30:00Z

Links: CVE-2025-47933 - Bugzilla