CVE Tools

Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

The Hacker NewsBy The Hacker News

Researchrepo-server

Our summary

Argo CD’s repo-server component contains an unpatched, unauthenticated remote code execution weakness that can allow attackers to run commands if they can reach its internal gRPC port, potentially leading to full Kubernetes cluster compromise. The issue affects Argo CD v2.13.3 and has no CVE or fixed release; researchers at Synacktiv report the flaw abuses kustomize’s --helm-command handling to execute attacker-controlled scripts. This matters because compromised repo-server access can be chained with prior exposure of Argo CD’s Redis cache behavior, re-enabling deployment poisoning similar to CVE-2024-31989—so administrators should verify Kubernetes network policies restrict repo-server and Redis access.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store