Executive brief
Argo CD, a tool used to automate the deployment of applications to Kubernetes, contains a vulnerability that could expose sensitive information. Under certain conditions, the system's 'diff' feature—which shows changes between intended and actual configurations—may accidentally reveal passwords or other secrets in the user interface or command-line tools. This could allow an attacker with limited access to the system to view confidential credentials, potentially leading to unauthorized access to other services.
Technical details
A vulnerability in Argo CD's ServerSideDiff component allows for the exposure of sensitive information from Kubernetes Secrets. The root cause is that the `HideSecretData` function fails to fully sanitize `ResourceDiff.TargetState` and `LiveState` objects, specifically when sensitive data is embedded within the `kubectl.kubernetes.io/last-applied-configuration` annotation. An attacker with low-privileged network access to the Argo CD UI or CLI can view these unsanitized diffs to extract `data`, `stringData`, and sensitive annotations. The issue is fixed by ensuring `HideSecretData` is correctly applied to server-side diff results and removing the last-applied-configuration annotation from comparison states.
Affected products
- argoproj Argo CD >= 3.2.0, < 3.2.12; >= 3.3.9, < 3.3.10; >= 3.4.1, < 3.4.2
Timeline
- 2026-07-15: advisory
- 2026-07-15: disclosed
- 2026-05-10: patched
References
- https://github.com/argoproj/argo-cd/commit/7879e6322465080a82d152bf00f2b92e0f36c658
- https://github.com/argoproj/argo-cd/commit/87e9148320749693624d08e3d6fa2cc217c672a0
- https://github.com/argoproj/argo-cd/commit/ac11bec9986807adc8886ef1181eced7347ef5c6
- https://github.com/argoproj/argo-cd/commit/bcb4298afc9fcff5f5d69f4e1db2d0a75983f42c
- https://github.com/argoproj/argo-cd/releases/tag/v3.2.12
- https://github.com/argoproj/argo-cd/releases/tag/v3.3.10
- https://github.com/argoproj/argo-cd/releases/tag/v3.4.2