What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck). The MCP client's http layer builds a delete URL from the applicationName argument with no normalization of dot segments.
Why it matters
Argo CD MCP servers connect agents to GitOps control planes with high-privilege tokens; a route-smuggling path traversal turns a single delete_application tool into arbitrary destructive DELETE calls when steered by prompt injection.
Attack vector
Unvalidated applicationName values in delete_application are concatenated into the API path; dot-segment values like ../repositories/ make authenticated DELETE requests hit other Argo CD endpoints (repositories, clusters, projects) within the token's RBAC (CWE-22).
Affected systems
argocd-mcp (Argo CD MCP Server) <= 0.9.0 — delete_application tool
Mitigation
Upgrade past 0.9.0; validate applicationName against an allowlist and pin the tool to the application path. See VulnCheck advisory.