PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108585 argoproj-labs CVE debrief

CVE-2026-108585 is a path traversal vulnerability in the argocd-mcp (Argo CD MCP Server) through version 0.9.0, affecting the delete_application tool. This allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests, potentially deleting repositories, clusters, or projects within the token's RBAC permissions.

Vendor
argoproj-labs
Product
argocd-mcp
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for Argo CD MCP Server deployments should assess exposure to this vulnerability and prioritize verification of the version in use. System administrators and security teams should consider implementing compensating controls to restrict access to sensitive API endpoints and monitor for suspicious activity related to authenticated DELETE requests.

Why it matters

CVE-2026-108585 is a path traversal vulnerability in argocd-mcp (Argo CD MCP Server) through version 0.9.0, allowing MCP clients to reach unintended API endpoints via unvalidated applicationName values. Defenders should prioritize verifying the version in use, assessing exposure, and implementing compensating controls.

  • Verify the version of argocd-mcp in use and assess exposure to the delete_application tool.
  • Implement compensating controls to restrict access to sensitive API endpoints.
  • Monitor for suspicious activity related to authenticated DELETE requests.

Technical summary

The argocd-mcp (Argo CD MCP Server) through version 0.9.0 contains a path traversal vulnerability in the delete_application tool. This allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests, potentially deleting repositories, clusters, or projects within the token's RBAC permissions.

Defensive priority

Defenders should prioritize verifying the version of argocd-mcp in use, assessing exposure to the delete_application tool, and implementing compensating controls to restrict access to sensitive API endpoints.

Recommended defensive actions

  • Verify the version of argocd-mcp in use and assess exposure to the delete_application tool.
  • Implement compensating controls to restrict access to sensitive API endpoints.
  • Monitor for suspicious activity related to authenticated DELETE requests.
  • Consider upgrading to a version of argocd-mcp that addresses this vulnerability.
  • Review and update access controls for MCP clients to prevent unauthorized access.
  • Conduct regular security audits to identify and address potential vulnerabilities.
  • Engage with the Argo CD community or vendors for support and guidance on mitigating this vulnerability.

Evidence notes

The CVE record and source references provide details on the vulnerability, including its description, affected versions, and potential impact. However, the corpus does not establish specific exploitation instances, victims, or business impacts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108585 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108585

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108585 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108585

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.