89 lines
5.0 KiB
Markdown
89 lines
5.0 KiB
Markdown
---
|
|
source_url: "https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql"
|
|
ingested: 2026-07-02
|
|
sha256: a73b3846df3ffee260543bd536c97d3b5c41cd6f2a58625c4bc3688c92e3c91b
|
|
discovered_from:
|
|
platform: discord
|
|
channel_id: "1028287639918497822"
|
|
channel_name: "chat"
|
|
message_id: "1522208455849410620"
|
|
author_id: "890908900520505354"
|
|
posted_at: "2026-07-02T11:52:57.140000000Z"
|
|
message_excerpt: "https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql"
|
|
---
|
|
Written by Hugo Vincent - 01/07/2026 - in Pentest \- [Download](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#)
|
|
|
|
Synacktiv has discovered an unauthenticated arbitrary code execution vulnerability in ArgoCD's repo-server component, potentially allowing full cluster compromise. This article explains how the vulnerability was identified using CodeQL, details the exploitation process to gain control over the underlying Kubernetes cluster, and introduces a tool for automating the attack.
|
|
|
|
[^1]:
|
|
|
|
[^undefined]: [1.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref1_03mxmnw) [https://www.synacktiv.com/publications/hijacking-github-runners-to-comp…](https://www.synacktiv.com/publications/hijacking-github-runners-to-compromise-the-organization)
|
|
|
|
[^undefined]:
|
|
|
|
[^2]:
|
|
|
|
[^undefined]: [2.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref2_oyzptip) [https://www.synacktiv.com/publications/github-actions-exploitation-depe…](https://www.synacktiv.com/publications/github-actions-exploitation-dependabot)
|
|
|
|
[^undefined]:
|
|
|
|
[^3]:
|
|
|
|
[^undefined]: [3.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref3_zxogqs9) [https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and…](https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and-tricks)
|
|
|
|
[^undefined]:
|
|
|
|
[^4]:
|
|
|
|
[^undefined]: [4.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref4_iekjxzz) [https://www.synacktiv.com/publications/github-actions-exploitation-untr…](https://www.synacktiv.com/publications/github-actions-exploitation-untrusted-input)
|
|
|
|
[^undefined]:
|
|
|
|
[^5]:
|
|
|
|
[^undefined]: [5.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref5_bshs0nc) [https://www.synacktiv.com/publications/azure-devops-build-agent-analysi…](https://www.synacktiv.com/publications/azure-devops-build-agent-analysis)
|
|
|
|
[^undefined]:
|
|
|
|
[^6]:
|
|
|
|
[^undefined]: [6.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref6_ceaf9bn) [https://www.synacktiv.com/en/publications/finding-gadgets-like-its-2022](https://www.synacktiv.com/en/publications/finding-gadgets-like-its-2022)
|
|
|
|
[^undefined]:
|
|
|
|
[^7]:
|
|
|
|
[^undefined]: [7.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref7_g1n134i) [https://github.com/GitHubSecurityLab/CodeQL-Community-Packs/](https://github.com/GitHubSecurityLab/CodeQL-Community-Packs/)
|
|
|
|
[^undefined]:
|
|
|
|
[^8]:
|
|
|
|
[^undefined]: [8.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref8_ueww9rw) [https://github.com/trailofbits/codeql-queries](https://github.com/trailofbits/codeql-queries)
|
|
|
|
[^undefined]:
|
|
|
|
[^9]:
|
|
|
|
[^undefined]: [9.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref9_up058wp) [https://codeql.github.com/docs/codeql-language-guides/customizing-libra…](https://codeql.github.com/docs/codeql-language-guides/customizing-library-models-for-go/)
|
|
|
|
[^undefined]:
|
|
|
|
[^10]:
|
|
|
|
[^undefined]: [10.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref10_9bicpt3) [https://cycode.com/blog/revealing-argo-cd-critical-vulnerability/](https://cycode.com/blog/revealing-argo-cd-critical-vulnerability/)
|
|
|
|
[^undefined]:
|
|
|
|
[^11]:
|
|
|
|
[^undefined]: [11.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref11_yqb1191) [https://github.com/BishopFox/badPods/blob/main/manifests/everything-all…](https://github.com/BishopFox/badPods/blob/main/manifests/everything-allowed/deployment/everything-allowed-exec-deployment.yaml)
|
|
|
|
[^undefined]:
|
|
|
|
[^12]:
|
|
|
|
[^undefined]: [12.](https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql#footnoteref12_a9i02sg) [https://www.ledger.com/argo-cd-security-misconfiguration-adventures](https://www.ledger.com/argo-cd-security-misconfiguration-adventures)
|
|
|
|
[^undefined]:
|