YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0018

Incident record

An Argo CD MCP server listened on every interface and lent out the operator’s token

Severity
Critical
Status
Patched
Type
Agent Hijack
Target
argocd-mcp 0.8.0
Actor
researcher
CVE
CVE-2026-82456

What happened

argocd-mcp 0.8.0 bound its MCP HTTP transport to every network interface and accepted sessions without caller credentials whenever an API token was configured. Anyone who could reach the listener could use the operator’s stored token to create applications, request syncs and change Argo CD resources.

Both NVD and VulnCheck give it the maximum score, 10.0 critical on CVSS 3.1 and 4.0. The pattern is the one running through this month’s MCP advisories: a server written for a developer’s own machine, where binding to all interfaces and skipping authentication are conveniences, then deployed somewhere reachable with a privileged token in its environment. Fixed in 0.9.0.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026