StackRadar

CVE-2025-23216

Medium

Advisory

Published 30 Jan 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 2
affected packages

Argo CD does not scrub secret values from patch errors

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
github.com/argoproj/argo-cd/v2golangv2.4.7, v2.4.11, v2.7.2, v2.7.8+4 more2.11.13, 2.13.48
github.com/argoproj/argo-cdgolangv1.5.8no fix listed1
OSV records
GHSA-47g2-qmh2-749v
Also known as
BIT-argo-cd-2025-23216, GO-2025-3433

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2025-23216.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/argoproj/argo-cd/v2@v2.8.16
2.11.13

Open the chart page →

3,793
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-23216.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/argoproj/argo-cd/v2@v2.8.6
2.11.13

Open the chart page →

10,315
devtron-in-clustercddevtron0.10.21 of 2See more

devtron-in-clustercd devtron 0.10.2

1 of the 2 container images this version deploys carry CVE-2025-23216.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.11.13

Open the chart page →

5,039
devtron-in-clustercddevtron-labs0.10.21 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

1 of the 2 container images this version deploys carry CVE-2025-23216.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.11.13

Open the chart page →

5,039
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-23216.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/argoproj/argo-cd/v2@v2.4.11
2.11.13

Open the chart page →

13,450
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-23216.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/argoproj/argo-cd/v2@v2.7.8
2.11.13

Open the chart page →

2,607
argocd-extra-app-info-exportermikejohVerified publisher0.1.121 of 1See more

argocd-extra-app-info-exporter mikejoh 0.1.12

1 of the 1 container images this version deploys carry CVE-2025-23216.

Container imageDigestPackageFixed in
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
github.com/argoproj/argo-cd/v2@v2.13.3
2.13.4

Open the chart page →

1,334
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2025-23216.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.11.13

Open the chart page →

5,039
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-23216.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/argoproj/argo-cd/v2@v2.9.3
2.11.13

Open the chart page →

2,314
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2025-23216.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
github.com/argoproj/argo-cd@v1.5.8
no fix listed

Open the chart page →

6,671
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-23216.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
github.com/argoproj/argo-cd/v2@v2.4.7
2.11.13

Open the chart page →

1,985

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/argoproj/argo-cd/v2@v2.7.2
2.11.13
3
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
github.com/argoproj/argo-cd/v2@v2.13.3
2.13.4
1
sikalabs/slu:v0.72.07bd267f30247
github.com/argoproj/argo-cd/v2@v2.9.3
2.11.13
1
stakater/workshop-operator:v0.0.3897bf456cc97c
github.com/argoproj/argo-cd@v1.5.8
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/argoproj/argo-cd/v2@v2.4.11
2.11.13
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/argoproj/argo-cd/v2@v2.8.6
2.11.13
1
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
github.com/argoproj/argo-cd/v2@v2.4.7
2.11.13
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/argoproj/argo-cd/v2@v2.7.8
2.11.13
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/argoproj/argo-cd/v2@v2.8.16
2.11.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.