MEDIUM
argoproj-labs
CVE published 2026-10-10
CVE-2026-108585
CVE-2026-108585 is a path traversal vulnerability in the argocd-mcp (Argo CD MCP Server) through version 0.9.0, affecting the delete_application tool. This allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests, potentially deleting repositorie [truncated]