Sceawere
Vulnerability Detail
CVE-2026-108585UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Argo CD MCP Path Traversal
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 3h ago
- Vendor
- argoproj-labs
- Product
- argocd-mcp
- Attack Type
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
argocd-mcp (Argo CD MCP Server) through 0.9.0 contains a path traversal vulnerability in the delete_application tool that allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests deleting repositories, clusters, or projects within the token's RBAC permissions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-10T17:17:00.437Z",
"pubdate": "2026-10-10T17:17:00.437Z",
"executiveSummary": "Argo CD MCP Server through version 0.9.0 is susceptible to a path traversal vulnerability located within the delete_application tool.\nThe vulnerability arises from insufficient sanitization of the applicationName parameter, enabling unauthorized access to unintended API endpoints.\nAn attacker or a prompt-injected LLM can supply crafted dot-segment sequences (e.g., ../repositories/) to manipulate the request path, effectively escalating an application deletion request into arbitrary DELETE operations against other API resources.\nThe impact is significant, as successful exploitation allows for the deletion of critical infrastructure components, including repositories, clusters, and projects, contingent upon the RBAC permissions associated with the client's authentication token.\nThis vulnerability represents a high-risk scenario for environments utilizing Argo CD MCP, as it facilitates unauthorized destructive actions within the target Kubernetes cluster management plane.\nExploitation does not require external network exposure beyond the standard MCP client-server communication channel, provided the attacker can influence the tool input.",
"technicalDetails": "The root cause of this vulnerability is improper input validation within the delete_application function of the Argo CD MCP Server. The server implementation fails to normalize or restrict the applicationName input string before incorporating it into the API request path sent to the Argo CD backend.\nSpecifically, the input field is vulnerable to path traversal patterns, allowing an attacker to escape the intended API context. By injecting dot-segment sequences such as '../repositories/' or '../clusters/', the attacker forces the client to traverse outside the '/applications/' endpoint scope.\nThe attack flow proceeds as follows: First, the attacker triggers the delete_application tool through an MCP client. Second, instead of providing a valid application identifier, the attacker provides a malicious payload containing traversal characters. Third, the MCP server improperly concatenates this unsanitized string into the URI structure of the outgoing HTTP request. Finally, the Argo CD API receives the malformed request, interpreting it as a legitimate call to a different resource type, such as deleting a repository or a cluster.\nThe exploit relies on the underlying RBAC permissions assigned to the authentication token used by the MCP server. If the token possesses broad permissions, the attacker can leverage this path traversal to delete any resource that supports the DELETE method within the Argo CD API, provided the traversal payload can navigate to the correct resource endpoint.\nThis flaw is persistent across all versions up to and including 0.9.0. Because the vulnerability exists within the logic of the tool itself, any client capable of invoking the delete_application function can serve as a vector, including automated agents or models susceptible to indirect prompt injection. The integrity of the Argo CD instance is compromised once the attacker successfully reaches sensitive endpoints, leading to potentially irreversible administrative or infrastructure-level disruptions."
}