CVE-2026-45738: Argoproj Argo Cd

High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/src/app/applications/components/application-summary/application-summary.tsx in the Summary tab URLs section as anchor href values without URL validation, allowing javascript: execution in a higher-privileged user's authenticated Argo CD origin session. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.

Affected products

  • Argoproj Argo Cd: before 3.2.12 (fixed in 3.2.12); from 3.3.0, before 3.3.10 (fixed in 3.3.10); from 3.4.0, before 3.4.2 (fixed in 3.4.2)

Published 2026-07-15. Last modified 2026-07-20.