Description


argocd-mcp (Argo CD MCP Server) through 0.9.0 contains a path traversal vulnerability in the delete_application tool that allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests deleting repositories, clusters, or projects within the token's RBAC permissions.

Related CPE's


Could not find any relations

Weaknesses



CWE-22

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

5.4 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-10T17:17:00.437Z

1 hour ago

Last modified

2026-10-10T17:17:00.550Z

1 hour ago