Back Feeds.4Sysops Unpatched Argo CD vulnerability allows remote code execution and cluster takeover
Argo CD, a popular GitOps tool for automating software deployments to Kubernetes, contains an unpatched vulnerability in its repo-server component. Security researchers discovered that an unauthenticated attacker can achieve remote code execution if they gain access to the service's internal gRPC endpoint. The flaw stems from how the system handles Kustomize options, allowing malicious actors to inject attacker-controlled settings through a crafted request. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
