argocd-mcp (Argo CD MCP Server) through 0.9.0 contains a path traversal vulnerability in the delete_application tool that allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests deleting repositories, clusters, or projects within the token's RBAC permissions.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj-labs
Argoproj-labs argocd-mcp |
|
| Vendors & Products |
Argoproj-labs
Argoproj-labs argocd-mcp |
Sat, 10 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | argocd-mcp (Argo CD MCP Server) through 0.9.0 contains a path traversal vulnerability in the delete_application tool that allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests deleting repositories, clusters, or projects within the token's RBAC permissions. | |
| Title | argocd-mcp through 0.9.0 Path Traversal via delete_application Tool | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T16:14:09.568Z
Reserved: 2026-10-10T16:07:39.993Z
Link: CVE-2026-108585
No data.
Status : Deferred
Published: 2026-10-10T17:17:00.437
Modified: 2026-10-10T17:17:00.550
Link: CVE-2026-108585
No data.
OpenCVE Enrichment
Updated: 2026-10-10T17:30:05Z
Weaknesses