Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108585 1 Argoproj-labs 1 Argocd-mcp 2026-10-10 5.4 Medium
argocd-mcp (Argo CD MCP Server) through 0.9.0 contains a path traversal vulnerability in the delete_application tool that allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests deleting repositories, clusters, or projects within the token's RBAC permissions.
CVE-2026-82456 1 Argoproj-labs 1 Argocd-mcp 2026-09-24 10 Critical
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.