PatchSiren cyber security CVE debrief
CVE-2026-108585 argoproj-labs CVE debrief
CVE-2026-108585 is a path traversal vulnerability in the argocd-mcp (Argo CD MCP Server) through version 0.9.0, affecting the delete_application tool. This allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests, potentially deleting repositories, clusters, or projects within the token's RBAC permissions.
- Vendor
- argoproj-labs
- Product
- argocd-mcp
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for Argo CD MCP Server deployments should assess exposure to this vulnerability and prioritize verification of the version in use. System administrators and security teams should consider implementing compensating controls to restrict access to sensitive API endpoints and monitor for suspicious activity related to authenticated DELETE requests.
Why it matters
CVE-2026-108585 is a path traversal vulnerability in argocd-mcp (Argo CD MCP Server) through version 0.9.0, allowing MCP clients to reach unintended API endpoints via unvalidated applicationName values. Defenders should prioritize verifying the version in use, assessing exposure, and implementing compensating controls.
- Verify the version of argocd-mcp in use and assess exposure to the delete_application tool.
- Implement compensating controls to restrict access to sensitive API endpoints.
- Monitor for suspicious activity related to authenticated DELETE requests.
Technical summary
The argocd-mcp (Argo CD MCP Server) through version 0.9.0 contains a path traversal vulnerability in the delete_application tool. This allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests, potentially deleting repositories, clusters, or projects within the token's RBAC permissions.
Defensive priority
Defenders should prioritize verifying the version of argocd-mcp in use, assessing exposure to the delete_application tool, and implementing compensating controls to restrict access to sensitive API endpoints.
Recommended defensive actions
- Verify the version of argocd-mcp in use and assess exposure to the delete_application tool.
- Implement compensating controls to restrict access to sensitive API endpoints.
- Monitor for suspicious activity related to authenticated DELETE requests.
- Consider upgrading to a version of argocd-mcp that addresses this vulnerability.
- Review and update access controls for MCP clients to prevent unauthorized access.
- Conduct regular security audits to identify and address potential vulnerabilities.
- Engage with the Argo CD community or vendors for support and guidance on mitigating this vulnerability.
Evidence notes
The CVE record and source references provide details on the vulnerability, including its description, affected versions, and potential impact. However, the corpus does not establish specific exploitation instances, victims, or business impacts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108585 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108585
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108585 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108585
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj-labs/mcp-for-argocd
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj-labs/mcp-for-argocd/blob/28d15ca69b0c31387cc6ec73d201fd13c5d22b6a/src/argocd/client.ts
-
Source reference
Unverified legacy reference
URL: https://github.com/argoproj-labs/mcp-for-argocd/blob/28d15ca69b0c31387cc6ec73d201fd13c5d22b6a/src/argocd/http.ts
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind/argocd-mcp-delete-application-route-smuggling
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/argocd-mcp-through-0.9.0-path-traversal-via-delete-application-tool
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.