CVE-2026-108585
argocd-mcp through 0.9.0 Path Traversal via delete_application Tool
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
argocd-mcp (Argo CD MCP Server) through 0.9.0 contains a path traversal vulnerability in the delete_application tool that allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests deleting repositories, clusters, or projects within the token's RBAC permissions.
| CWE | CWE-22 |
| Vendor | argoproj-labs |
| Product | argocd-mcp |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for argoproj-labs argocd-mcp
Be the first to know when new medium vulnerabilities affecting argoproj-labs argocd-mcp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Affected Versions
argoproj-labs / argocd-mcp
0 โค 0.9.0
References
hackmd.io: https://hackmd.io/@haind/argocd-mcp-delete-application-route-smuggling github.com: https://github.com/argoproj-labs/mcp-for-argocd/blob/28d15ca69b0c31387cc6ec73d201fd13c5d22b6a/src/argocd/client.ts#L115-L139 github.com: https://github.com/argoproj-labs/mcp-for-argocd/blob/28d15ca69b0c31387cc6ec73d201fd13c5d22b6a/src/argocd/http.ts#L86-L91 github.com: https://github.com/argoproj-labs/mcp-for-argocd vulncheck.com: https://www.vulncheck.com/advisories/argocd-mcp-through-0.9.0-path-traversal-via-delete-application-tool
Credits
HaiND from the Post and Telecommunication Institute of Technology