Container Journal
Read post

Security Flaw in Argo CD Can Let Attackers Take Over Kubernetes Clusters

Synacktiv researchers have disclosed an unpatched vulnerability in Argo CD, the widely-used GitOps deployment tool, that allows unauthenticated remote code execution and full takeover of Kubernetes clusters. Reported to maintainers in January 2025, the flaw remains unpatched over a year later. The vulnerability resides in Argo CD's repo-server component, whose gRPC interface lacks authentication. An attacker with internal cluster access — achievable via a compromised pod — can inject malicious KustomizeOptions to execute arbitrary code, access the Redis database, and deploy arbitrary Kubernetes manifests. Synacktiv recommends applying strict Kubernetes network policies as a mitigation until a fix is released, and is temporarily withholding their exploitation tool to give defenders time to act.

    #security#kubernetes#gitops#argocd
Jul 07•5m read time•From cloudnativenow.com
Post cover image
Table of contents
Argo CD Sits at the Top of the Charts‘An Attractive Target for Attackers’Some Steps Needed for ExploitationAccessing the Redis DatabaseRelated
21K Impressions
Container Journal's image
Container Journal

Container Journal is a leading source of news, analysis, and insights on containerization, Kubernete...

100 Followers

•

207 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard