github.com/argoproj/argo-cd/v3 is vulnerable to Path Traversal
70
High Risk
Affected versions of this package are vulnerable to Path Traversal in UI Asset Handling, where insufficient input sanitization allows remote attackers to access arbitrary files outside the web root by crafting malicious URLs containing directory traversal sequences (e.g., ../). An attacker could exploit this vulnerability by manipulating the r.URL.Path parameter to bypass intended directory restrictions, for example, requesting https://target/%2e%2e/etc/passwd would traverse outside the UI asset directory.
You are affected if you are using a version that falls within the vulnerable range.
github.com/argoproj/argo-cd/v3 is vulnerable to Path Traversal in versions 3.0.0 - 3.0.12.
Upgrade the github.com/argoproj/argo-cd/v3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant