{"id":"CVE-2026-45738","aliases":["BIT-argo-cd-2026-45738","GHSA-h98r-wv3h-fr38","GO-2026-5418"],"url":"https://o3.security/vulnerability/CVE-2026-45738","summary":"Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation","details":"Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/src/app/applications/components/application-summary/application-summary.tsx in the Summary tab URLs section as anchor href values without URL validation, allowing javascript: execution in a higher-privileged user's authenticated Argo CD origin session. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.","published":"2026-07-15T19:54:51.634Z","modified":"2026-08-12T03:51:26.859952880Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"},"epss":{"score":0.00392,"percentile":0.32418,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/argoproj/argo-cd/v3","fixedVersion":"3.2.12"},{"ecosystem":"Go","name":"github.com/argoproj/argo-cd/v3","fixedVersion":"3.3.10"},{"ecosystem":"Go","name":"github.com/argoproj/argo-cd/v3","fixedVersion":"3.4.2"},{"ecosystem":"Go","name":"github.com/argoproj/argo-cd/v2","fixedVersion":null},{"ecosystem":"Go","name":"github.com/argoproj/argo-cd","fixedVersion":null}],"fix":{"url":"https://github.com/argoproj/argo-cd/commit/00f83c41dcfd879f34f8e0248c860d704b41cf0f","label":"argoproj/argo-cd@00f83c4"},"references":[{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v3.2.12"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v3.3.10"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v3.4.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45738.json"},{"type":"ADVISORY","url":"https://github.com/argoproj/argo-cd/security/advisories/GHSA-h98r-wv3h-fr38"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45738"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/00f83c41dcfd879f34f8e0248c860d704b41cf0f"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/35ea43c537d6e8948e67f347317fc4f88b325122"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/c8df5ff7acc403adcee1256da5d87081cd52f0a6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.859952880Z"}}