<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Argo Cd on AI VOID</title><link>https://ai-blog.noorshomelab.dev/tags/argo-cd/</link><description>Recent content in Argo Cd on AI VOID</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 26 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://ai-blog.noorshomelab.dev/tags/argo-cd/index.xml" rel="self" type="application/rss+xml"/><item><title>Critical Argo CD API Flaw (CVE-2025-55190) Leaks Repository Credentials</title><link>https://ai-blog.noorshomelab.dev/releases/argo-cd-cve-2025-55190-repository-credentials-leak/</link><pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate><guid>https://ai-blog.noorshomelab.dev/releases/argo-cd-cve-2025-55190-repository-credentials-leak/</guid><description>&lt;blockquote&gt;
&lt;p&gt;🚨 &lt;strong&gt;CRITICAL&lt;/strong&gt; — Security fix. Upgrade immediately.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Version:&lt;/strong&gt; 3.1.2, 3.0.14, 2.14.16, 2.13.9 | &lt;strong&gt;Released:&lt;/strong&gt; 2026-05-26 | &lt;strong&gt;Upgrade from:&lt;/strong&gt; Multiple affected versions (see details)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="release-at-a-glance"&gt;Release at a Glance&lt;/h2&gt;
&lt;p&gt;A critical security vulnerability, &lt;strong&gt;CVE-2025-55190&lt;/strong&gt;, has been identified and patched in Argo CD. This flaw allows project-level API tokens to expose sensitive repository credentials, posing a significant risk to CI/CD pipelines.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s what you need to know immediately:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Critical Vulnerability:&lt;/strong&gt; Project-level API tokens in affected Argo CD versions can retrieve repository usernames and passwords, even without explicit secret access permissions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Immediate Action Required:&lt;/strong&gt; All users running affected Argo CD versions &lt;strong&gt;must upgrade immediately&lt;/strong&gt; to a patched version.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Impact:&lt;/strong&gt; This vulnerability can lead to unauthorized access to your source code repositories, enabling supply chain attacks and compromising your infrastructure.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Versions:&lt;/strong&gt; Upgrade to Argo CD &lt;strong&gt;3.1.2, 3.0.14, 2.14.16, or 2.13.9&lt;/strong&gt; to remediate this issue.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="security-fixes-cve-2025-55190"&gt;Security Fixes: CVE-2025-55190&lt;/h2&gt;
&lt;p&gt;Today, we are releasing urgent patches for Argo CD to address a critical security vulnerability, &lt;strong&gt;CVE-2025-55190&lt;/strong&gt;, titled &amp;ldquo;Project API Token Exposes Repository Credentials.&amp;rdquo; This flaw was discovered by Ashish Goyal and impacts the confidentiality of your repository access.&lt;/p&gt;</description></item></channel></rss>