GHSA-f7cg-qc77-hh95MediumCVSS 5.4

argocd-mcp (Argo CD MCP Server) through 0.9.0 contains a path traversal vulnerability in the...

Published
October 10, 2026
Last Modified
October 10, 2026

🔗 CVE IDs covered (1)

📋 Description

argocd-mcp (Argo CD MCP Server) through 0.9.0 contains a path traversal vulnerability in the delete_application tool that allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests deleting repositories, clusters, or projects within the token's RBAC permissions.

🔗 References (7)