GHSA-p2x5-x87w-v2xjCriticalCVSS 10.0

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions...

Published
August 29, 2026
Last Modified
August 29, 2026

🔗 CVE IDs covered (1)

📋 Description

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.

🔗 References (5)