PatchSiren

argoproj-labs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM argoproj-labs CVE published 2026-10-10

CVE-2026-108585

CVE-2026-108585 is a path traversal vulnerability in the argocd-mcp (Argo CD MCP Server) through version 0.9.0, affecting the delete_application tool. This allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests, potentially deleting repositorie [truncated]