Sceawere

Vulnerability Detail

CVE-2026-108585UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Argo CD MCP Path Traversal

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
argoproj-labs
Product
argocd-mcp
Attack Type
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

argocd-mcp (Argo CD MCP Server) through 0.9.0 contains a path traversal vulnerability in the delete_application tool that allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests deleting repositories, clusters, or projects within the token's RBAC permissions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-10T17:17:00.437Z",
  "pubdate": "2026-10-10T17:17:00.437Z",
  "executiveSummary": "Argo CD MCP Server through version 0.9.0 is susceptible to a path traversal vulnerability located within the delete_application tool.\nThe vulnerability arises from insufficient sanitization of the applicationName parameter, enabling unauthorized access to unintended API endpoints.\nAn attacker or a prompt-injected LLM can supply crafted dot-segment sequences (e.g., ../repositories/) to manipulate the request path, effectively escalating an application deletion request into arbitrary DELETE operations against other API resources.\nThe impact is significant, as successful exploitation allows for the deletion of critical infrastructure components, including repositories, clusters, and projects, contingent upon the RBAC permissions associated with the client's authentication token.\nThis vulnerability represents a high-risk scenario for environments utilizing Argo CD MCP, as it facilitates unauthorized destructive actions within the target Kubernetes cluster management plane.\nExploitation does not require external network exposure beyond the standard MCP client-server communication channel, provided the attacker can influence the tool input.",
  "technicalDetails": "The root cause of this vulnerability is improper input validation within the delete_application function of the Argo CD MCP Server. The server implementation fails to normalize or restrict the applicationName input string before incorporating it into the API request path sent to the Argo CD backend.\nSpecifically, the input field is vulnerable to path traversal patterns, allowing an attacker to escape the intended API context. By injecting dot-segment sequences such as '../repositories/' or '../clusters/', the attacker forces the client to traverse outside the '/applications/' endpoint scope.\nThe attack flow proceeds as follows: First, the attacker triggers the delete_application tool through an MCP client. Second, instead of providing a valid application identifier, the attacker provides a malicious payload containing traversal characters. Third, the MCP server improperly concatenates this unsanitized string into the URI structure of the outgoing HTTP request. Finally, the Argo CD API receives the malformed request, interpreting it as a legitimate call to a different resource type, such as deleting a repository or a cluster.\nThe exploit relies on the underlying RBAC permissions assigned to the authentication token used by the MCP server. If the token possesses broad permissions, the attacker can leverage this path traversal to delete any resource that supports the DELETE method within the Argo CD API, provided the traversal payload can navigate to the correct resource endpoint.\nThis flaw is persistent across all versions up to and including 0.9.0. Because the vulnerability exists within the logic of the tool itself, any client capable of invoking the delete_application function can serve as a vector, including automated agents or models susceptible to indirect prompt injection. The integrity of the Argo CD instance is compromised once the attacker successfully reaches sensitive endpoints, leading to potentially irreversible administrative or infrastructure-level disruptions."
}
CVE-2026-108585: Argo CD MCP Path Traversal (MEDIUM Severity, CVSS: 5.4) | Sceawere