Vulnerability  ·  2026-10-11

argocd-mcp delete_application path traversal lets prompt-injected MCP clients DELETE Argo CD repos/clusters (CVSS 5.4)

VulnerabilityHigh impactGlobalCVE-2026-108585
Verified via NVD REST API (published 2026-10-10, VulnCheck). The MCP client's http layer builds a delete URL from the applicationName argument with no normalization of dot segments.
Argo CD MCP servers connect agents to GitOps control planes with high-privilege tokens; a route-smuggling path traversal turns a single delete_application tool into arbitrary destructive DELETE calls when steered by prompt injection.
Unvalidated applicationName values in delete_application are concatenated into the API path; dot-segment values like ../repositories/ make authenticated DELETE requests hit other Argo CD endpoints (repositories, clusters, projects) within the token's RBAC (CWE-22).
argocd-mcp (Argo CD MCP Server) <= 0.9.0 — delete_application tool
Upgrade past 0.9.0; validate applicationName against an allowlist and pin the tool to the application path. See VulnCheck advisory.
NVD CVE-2026-108585NVD REST APIVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →