<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T12:58:09.701797+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-eh36582</id>
    <title>Withdrawn: CLEANSTART-2026-EH36582 — Security fixes for CVE-2025-47912, CVE-2025-55190, CVE-2025-55191, CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-…</title>
    <updated>2026-10-07T12:58:09.773673+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: argo-cd</p>
<p>Multiple security vulnerabilities affect the argo-cd package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-eh36582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338281</id>
    <title>EUVD-2026-338281</title>
    <updated>2026-10-07T12:58:09.773768+00:00</updated>
    <content>EUVD-2026-338281</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338281"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45738</id>
    <title>fkie_cve-2026-45738</title>
    <updated>2026-10-07T12:58:09.773790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/src/app/applications/components/application-summary/application-summary.tsx in the Summary tab URLs section as anchor href values without URL validation, allowing javascript: execution in a higher-privileged user's authenticated Argo CD origin session. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45738"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h98r-wv3h-fr38</id>
    <title>GHSA-h98r-wv3h-fr38 — Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation</title>
    <updated>2026-10-07T12:58:09.773834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/argoproj/argo-cd/v3, Go: github.com/argoproj/argo-cd/v2, Go: github.com/argoproj/argo-cd</p>
<p>### Summary</p>
<p>A user with **application write access (developer role)** can set `link.argocd.argoproj.io/*` annotations on any ArgoCD Application. These annotation values are rendered in the Summary tab's **URLs section** as `&lt;a href&gt;` elements without URL validation. Using the pipe-separator trick (`Display Text | javascript:...`), an attacker can inject a `javascript:` URI while displaying a legitimate-looking label (e.g. `GitHub Repo`). When a higher-privileged user (admin) clicks the link, **arbitrary JavaScript executes in the ArgoCD origin context** in the admin's authenticated session context, enabling API exfiltration and privilege escalation from developer to admin.</p>
<p>### Details</p>
<p>**Vulnerable sink:** `ui/src/app/applications/components/application-summary/application-summary.tsx:277`</p>
<p>```tsx
const parts = (url || '').split('|');
&lt;a key={i} href={parts.length &gt; 1 ? parts[1] : parts[0]} target='_blank'&gt;
    {parts[0]}
&lt;/a&gt;
```</p>
<p>The annotation value is split on `|`. `parts[0]` becomes the visible link label; `parts[1]` becomes the `href`. **No call to `isValidURL()` is made**, unlike the protected `ApplicationURLs` component (`application-urls.tsx:72,80`) which does validate URLs and blocks `javascript:`. The `target='_blank'` opens a new tab that inherits the ArgoCD origin, giving the injected script same-origin fetch access to all ArgoCD APIs using the victim's authenticated session (credentialed `fetch()` calls).</p>
<p>**Root cause:** React 16.x does not block `javascript…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h98r-wv3h-fr38"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1566</id>
    <title>WID-SEC-W-2026-1566 — Argo CD: Mehrere Schwachstellen</title>
    <updated>2026-10-07T12:58:09.773992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Argo CD ausnutzen, um Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen, wodurch potenziell Administratorrechte erlangt werden können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1566"/>
  </entry>
</feed>
