Files
llm-wiki/raw/articles/synacktiv-argo-cd-codeql-rce-2026.md
2026-07-03 00:38:05 +09:00

89 lines
5.0 KiB
Markdown

---
source_url: "https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql"
ingested: 2026-07-02
sha256: a73b3846df3ffee260543bd536c97d3b5c41cd6f2a58625c4bc3688c92e3c91b
discovered_from:
platform: discord
channel_id: "1028287639918497822"
channel_name: "chat"
message_id: "1522208455849410620"
author_id: "890908900520505354"
posted_at: "2026-07-02T11:52:57.140000000Z"
message_excerpt: "https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql"
---
Written by Hugo Vincent - 01/07/2026 - in Pentest \- [Download](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#)
Synacktiv has discovered an unauthenticated arbitrary code execution vulnerability in ArgoCD's repo-server component, potentially allowing full cluster compromise. This article explains how the vulnerability was identified using CodeQL, details the exploitation process to gain control over the underlying Kubernetes cluster, and introduces a tool for automating the attack.
[^1]:
[^undefined]: [1.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref1_03mxmnw) [https://www.synacktiv.com/publications/hijacking-github-runners-to-comp…](https://www.synacktiv.com/publications/hijacking-github-runners-to-compromise-the-organization)
[^undefined]:
[^2]:
[^undefined]: [2.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref2_oyzptip) [https://www.synacktiv.com/publications/github-actions-exploitation-depe…](https://www.synacktiv.com/publications/github-actions-exploitation-dependabot)
[^undefined]:
[^3]:
[^undefined]: [3.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref3_zxogqs9) [https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and…](https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and-tricks)
[^undefined]:
[^4]:
[^undefined]: [4.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref4_iekjxzz) [https://www.synacktiv.com/publications/github-actions-exploitation-untr…](https://www.synacktiv.com/publications/github-actions-exploitation-untrusted-input)
[^undefined]:
[^5]:
[^undefined]: [5.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref5_bshs0nc) [https://www.synacktiv.com/publications/azure-devops-build-agent-analysi…](https://www.synacktiv.com/publications/azure-devops-build-agent-analysis)
[^undefined]:
[^6]:
[^undefined]: [6.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref6_ceaf9bn) [https://www.synacktiv.com/en/publications/finding-gadgets-like-its-2022](https://www.synacktiv.com/en/publications/finding-gadgets-like-its-2022)
[^undefined]:
[^7]:
[^undefined]: [7.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref7_g1n134i) [https://github.com/GitHubSecurityLab/CodeQL-Community-Packs/](https://github.com/GitHubSecurityLab/CodeQL-Community-Packs/)
[^undefined]:
[^8]:
[^undefined]: [8.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref8_ueww9rw) [https://github.com/trailofbits/codeql-queries](https://github.com/trailofbits/codeql-queries)
[^undefined]:
[^9]:
[^undefined]: [9.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref9_up058wp) [https://codeql.github.com/docs/codeql-language-guides/customizing-libra…](https://codeql.github.com/docs/codeql-language-guides/customizing-library-models-for-go/)
[^undefined]:
[^10]:
[^undefined]: [10.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref10_9bicpt3) [https://cycode.com/blog/revealing-argo-cd-critical-vulnerability/](https://cycode.com/blog/revealing-argo-cd-critical-vulnerability/)
[^undefined]:
[^11]:
[^undefined]: [11.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref11_yqb1191) [https://github.com/BishopFox/badPods/blob/main/manifests/everything-all…](https://github.com/BishopFox/badPods/blob/main/manifests/everything-allowed/deployment/everything-allowed-exec-deployment.yaml)
[^undefined]:
[^12]:
[^undefined]: [12.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref12_a9i02sg) [https://www.ledger.com/argo-cd-security-misconfiguration-adventures](https://www.ledger.com/argo-cd-security-misconfiguration-adventures)
[^undefined]: