High severity7.3GHSA Advisory· Published Jul 15, 2026· Updated Jul 20, 2026
CVE-2026-45738
CVE-2026-45738
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/src/app/applications/components/application-summary/application-summary.tsx in the Summary tab URLs section as anchor href values without URL validation, allowing javascript: execution in a higher-privileged user's authenticated Argo CD origin session. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/argoproj/argo-cd/v3Go | < 3.2.12 | 3.2.12 |
github.com/argoproj/argo-cd/v3Go | >= 3.3.0-rc1, < 3.3.10 | 3.3.10 |
github.com/argoproj/argo-cd/v3Go | >= 3.4.0-rc1, < 3.4.2 | 3.4.2 |
github.com/argoproj/argo-cd/v2Go | <= 2.14.21 | — |
github.com/argoproj/argo-cdGo | <= 1.8.7 | — |
Affected products
11- osv-coords9 versionspkg:bitnami/argo-cdpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:apk/chainguard/argo-cd-3.2pkg:apk/chainguard/argo-cd-3.2-compatpkg:apk/chainguard/argocd-image-updaterpkg:apk/chainguard/argocd-image-updater-fipspkg:apk/wolfi/argo-cd-3.2pkg:apk/wolfi/argo-cd-3.2-compatpkg:apk/wolfi/argocd-image-updater
< 3.2.12+ 8 more
- (no CPE)range: < 3.2.12
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
- (no CPE)range: < 3.2.12-r0
- (no CPE)range: < 3.2.12-r0
- (no CPE)range: < 1.2.0-r4
- (no CPE)range: < 1.2.0-r5
- (no CPE)range: < 3.2.12-r0
- (no CPE)range: < 3.2.12-r0
- (no CPE)range: < 1.2.0-r4
Patches
Vulnerability mechanics
References
8- github.com/argoproj/argo-cd/commit/00f83c41dcfd879f34f8e0248c860d704b41cf0fnvdPatch
- github.com/argoproj/argo-cd/commit/35ea43c537d6e8948e67f347317fc4f88b325122nvdPatch
- github.com/argoproj/argo-cd/commit/c8df5ff7acc403adcee1256da5d87081cd52f0a6nvdPatch
- github.com/argoproj/argo-cd/security/advisories/GHSA-h98r-wv3h-fr38nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-h98r-wv3h-fr38ghsaADVISORY
- github.com/argoproj/argo-cd/releases/tag/v3.2.12nvdRelease Notes
- github.com/argoproj/argo-cd/releases/tag/v3.3.10nvdRelease Notes
- github.com/argoproj/argo-cd/releases/tag/v3.4.2nvdRelease Notes
News mentions
0No linked articles in our index yet.