Skip to content
Threat Feed

Vendor

Argo Project

7 briefs RSS
critical advisory

Unauthenticated Remote Access in argocd-mcp via CVE-2026-82456

The argocd-mcp component version 0.8.0 insecurely binds its HTTP transport to all network interfaces and lacks authentication for MCP sessions when an API token is present, allowing remote attackers to perform unauthorized Argo CD resource modifications.

argocd-mcp vulnerability remote-code-execution cloud-native cicd
2t 1c
critical advisory

Unauthenticated Mutating Operations in Argo Rollouts Dashboard

Argo Rollouts dashboard versions 1.10.0 and earlier expose sensitive, mutating operations without authentication, authorization, or CSRF protection when bound to all network interfaces.

Argo Rollouts vulnerability cloud-native kubernetes
1t 1c
medium advisory

Argo CD: Multiple Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in Argo CD, including Cross-Site Scripting (XSS) and information disclosure flaws, which could lead to sensitive information exposure and potentially allow the attacker to gain administrator privileges.

Argo CD argo-cd vulnerability xss information-disclosure privilege-escalation cloud kubernetes
2t
high advisory

Unauthenticated Remote Code Execution in Argo CD Repo-Server (CVE-2026-15416)

An unauthenticated remote code execution vulnerability (CVE-2026-15416) exists in Argo CD's repo-server, the GitOps engine used by Red Hat OpenShift GitOps, allowing an attacker with network access to achieve RCE and deploy malicious Kubernetes resources, leading to potential cluster compromise.

Argo CD +3 kubernetes gitops rce cloud vulnerability cve
3t 1c
high advisory

Argo CD Helm Chart Vulnerability Exposes Internal APIs Leading to Cluster Compromise

A vulnerability, CVE-2026-62185, in the Argo CD Helm Chart before version 10.0.0 fails to install network policies by default, allowing any pod within a Kubernetes cluster to access critical Argo APIs, which attackers can exploit to achieve cluster compromise and remote code execution.

Argo CD Helm Chart kubernetes misconfiguration network-policy rce supply-chain
3t 1c 2i
high threat

Argo CD Stored XSS in Application Link Annotations Enables Privilege Escalation

Argo CD is vulnerable to stored cross-site scripting (XSS) via manipulated application link annotations, allowing a low-privileged user to execute arbitrary JavaScript in a higher-privileged user's session, leading to privilege escalation.

Argo CD xss privilege-escalation argocd cloud
2r 1t
medium advisory

Argo Workflows Controller Denial-of-Service via Malformed Pod Annotation

A malformed `workflows.argoproj.io/pod-gc-strategy` annotation in an Argo Workflow pod can trigger an unchecked array index in the `podGCFromPod()` function, leading to a controller-wide panic and denial-of-service.

Argo Workflows argo-workflows denial-of-service kubernetes
2r 2t