cbcvebase.
CVE-2026-45738
published 2026-07-15

CVE-2026-45738: Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can…

PriorityP353high8.7CVSS 3.1
AVNACLPRLUIRSCCHIHAN
EPSS
0.61%
46.7th percentile
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/src/app/applications/components/application-summary/application-summary.tsx in the Summary tab URLs section as anchor href values without URL validation, allowing javascript: execution in a higher-privileged user's authenticated Argo CD origin session. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.

Affected

11 ranges
VendorProductVersion rangeFixed in
argoprojargo-cd< 3.2.123.2.12
argoprojargo-cd
argoprojargo-cd
argoprojargo_cd< 3.2.123.2.12
argoprojargo_cd>= 3.3.0 < 3.3.103.3.10
argoprojargo_cd>= 3.4.0 < 3.4.23.4.2
github.comargoproj_argo-cd0 – 1.8.7
github.comargoproj_argo-cd_v20 – 2.14.21
github.comargoproj_argo-cd_v3>= 0 < 3.2.123.2.12
github.comargoproj_argo-cd_v3>= 3.3.0-rc1 < 3.3.103.3.10
github.comargoproj_argo-cd_v3>= 3.4.0-rc1 < 3.4.23.4.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.