CVE-2026-82456
CRITICAL
10,0
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
CRITICAL
10,0
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.
1327
Binding to an Unrestricted IP Address
IncompleteCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Amplification
Applicable Platforms
Languages:
Other
Technologies:
Web Server, Client Server, Cloud Computing
https://github.com/argoproj-labs/mcp-for-argocd
https://github.com/argoproj-labs/mcp-for-argocd/security/advisories/GHSA-rp45-5…
https://www.vulncheck.com/advisories/argocd-mcp-0.8.0-authentication-bypass-via…