CVE-2026-45738
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/src/app/applications/components/application-summary/application-summary.tsx in the Summary tab URLs section as anchor href values without URL validation, allowing javascript: execution in a higher-privileged user's authenticated Argo CD origin session. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.
In plain language
AI Worth attentionArgo CD versions before 3.2.12, 3.3.10, and 3.4.2 can let a developer trick an administrator into handing over control, so businesses running it should update.
Stored XSS in Argo CD application-link annotations permits an application writer to execute attacker-controlled JavaScript in an administrator's authenticated browser session.
What to do now
- Check whether you run Argo CD and whether any non-admin users can edit application links.
- Upgrade to 3.2.12, 3.3.10, or 3.4.2, depending on your current release branch.
- Until upgraded, remove untrusted application-link annotations and restrict application write access to trusted administrators.
- Review administrator activity and application changes after the upgrade.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-45738 and every CVE in our database. Create a free account — no credit card required.
Create Free Account