Cross-site scripting in Argo CD - CVE-2026-45738
Published: May 18, 2026
Argo CD
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in an administrator's session context and escalate privileges.
The vulnerability exists due to cross-site scripting in the application summary URLs section when rendering application link annotations. A remote user can set a crafted link.argocd.argoproj.io/* annotation containing a javascript: URI to execute arbitrary JavaScript in an administrator's session context and escalate privileges.
User interaction is required because a higher-privileged user must click the rendered link in the Summary tab.