VYPR

Mcp For Argocd

by Argoproj Labs

CVEs (1)

  • CVE-2026-82456CriAug 29, 2026
    risk 0.65cvss 10.0epss

    argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to…