Tools AI Risk Radar ai-incident-0018
Incident record
An Argo CD MCP server listened on every interface and lent out the operator’s token
- Severity
- Critical
- Status
- Patched
- Type
- Agent Hijack
- Target
- argocd-mcp 0.8.0
- Actor
- researcher
- CVE
- CVE-2026-82456
What happened
argocd-mcp 0.8.0 bound its MCP HTTP transport to every network interface and accepted sessions without caller credentials whenever an API token was configured. Anyone who could reach the listener could use the operator’s stored token to create applications, request syncs and change Argo CD resources.
Both NVD and VulnCheck give it the maximum score, 10.0 critical on CVSS 3.1 and 4.0. The pattern is the one running through this month’s MCP advisories: a server written for a developer’s own machine, where binding to all interfaces and skipping authentication are conveniences, then deployed somewhere reachable with a privileged token in its environment. Fixed in 0.9.0.
Sources
- GitHub Security Advisory GHSA-rp45-5x3v-48mrgithub.com/argoproj-labs/mcp-for-argocd/security/advisories/…
- VulnCheck advisorywww.vulncheck.com/advisories/argocd-mcp-0.8.0-authentication…
- NVD record, CVE-2026-82456nvd.nist.gov/vuln/detail/CVE-2026-82456
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026