CVE-2026-82456: Argoproj-Labs Argocd-Mcp

Critical severity, CVSS 10.0. EPSS: 1.7% chance of exploitation in the next 30 days.

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.

Affected products

  • Argoproj-Labs Argocd-Mcp: from 0.8.0, before 0.9.0 (fixed in 0.9.0)

Published 2026-08-29. Last modified 2026-09-23.