Executive brief
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd
Affected products
- Go github.com/argoproj/argo-cd
- Go github.com/argoproj/argo-cd/v3
- Go github.com/argoproj/argo-cd/v2
Junglewise Threat Intelligence
CVE-2025-59531 · Severity: low · CVSS 3.1 · Published 2025-10-23
Technologies: github.com/argoproj/argo-cd (Go), github.com/argoproj/argo-cd/v3 (Go), github.com/argoproj/argo-cd/v2 (Go). Vendors: Go.
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload in github.com/argoproj/argo-cd