<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 06:36:11 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-EH36582 — Security fixes for CVE-2025-47912, CVE-2025-55190, CVE-2025-55191, CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-eh36582</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-cd&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the argo-cd package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-cd&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the argo-cd package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-eh36582</guid>
    </item>
    <item>
      <title>EUVD-2026-338281</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338281</link>
      <description>EUVD-2026-338281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338281</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45738</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45738</link>
      <description>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/src/app/applications/components/application-summary/application-summary.tsx in the Summary tab URLs section as anchor href values without URL validation, allowing javascript: execution in a higher-privileged user&amp;#39;s authenticated Argo CD origin session. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/src/app/applications/components/application-summary/application-summary.tsx in the Summary tab URLs section as anchor href values without URL validation, allowing javascript: execution in a higher-privileged user&amp;#39;s authenticated Argo CD origin session. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45738</guid>
    </item>
    <item>
      <title>GHSA-h98r-wv3h-fr38 — Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h98r-wv3h-fr38</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v3, Go: github.com/argoproj/argo-cd/v2, Go: github.com/argoproj/argo-cd&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A user with **application write access (developer role)** can set `link.argocd.argoproj.io/*` annotations on any ArgoCD Application. These annotation values are rendered in the Summary tab&amp;#39;s **URLs section** as `&amp;lt;a href&amp;gt;` elements without URL validation. Using the pipe-separator trick (`Display Text | javascript:...`), an attacker can inject a `javascript:` URI while displaying a legitimate-looking label (e.g. `GitHub Repo`). When a higher-privileged user (admin) clicks the link, **arbitrary JavaScript executes in the ArgoCD origin context** in the admin&amp;#39;s authenticated session context, enabling API exfiltration and privilege escalation from developer to admin.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable sink:** `ui/src/app/applications/components/application-summary/application-summary.tsx:277`&lt;/p&gt;
&lt;p&gt;```tsx
const parts = (url || &amp;#39;&amp;#39;).split(&amp;#39;|&amp;#39;);
&amp;lt;a key={i} href={parts.length &amp;gt; 1 ? parts[1] : parts[0]} target=&amp;#39;_blank&amp;#39;&amp;gt;
    {parts[0]}
&amp;lt;/a&amp;gt;
```&lt;/p&gt;
&lt;p&gt;The annotation value is split on `|`. `parts[0]` becomes the visible link label; `parts[1]` becomes the `href`. **No call to `isValidURL()` is made**, unlike the protected `ApplicationURLs` component (`application-urls.tsx:72,80`) which does validate URLs and blocks `javascript:`. The `target=&amp;#39;_blank&amp;#39;` opens a new tab that inherits the ArgoCD origin, giving the injected script same-origin fetch access to all ArgoCD APIs using the victim&amp;#39;s authenticated session (credentialed `fetch()` calls).&lt;/p&gt;
&lt;p&gt;**Root cause:** React 16.x does not block `javascript…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v3, Go: github.com/argoproj/argo-cd/v2, Go: github.com/argoproj/argo-cd&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A user with **application write access (developer role)** can set `link.argocd.argoproj.io/*` annotations on any ArgoCD Application. These annotation values are rendered in the Summary tab&amp;#39;s **URLs section** as `&amp;lt;a href&amp;gt;` elements without URL validation. Using the pipe-separator trick (`Display Text | javascript:...`), an attacker can inject a `javascript:` URI while displaying a legitimate-looking label (e.g. `GitHub Repo`). When a higher-privileged user (admin) clicks the link, **arbitrary JavaScript executes in the ArgoCD origin context** in the admin&amp;#39;s authenticated session context, enabling API exfiltration and privilege escalation from developer to admin.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable sink:** `ui/src/app/applications/components/application-summary/application-summary.tsx:277`&lt;/p&gt;
&lt;p&gt;```tsx
const parts = (url || &amp;#39;&amp;#39;).split(&amp;#39;|&amp;#39;);
&amp;lt;a key={i} href={parts.length &amp;gt; 1 ? parts[1] : parts[0]} target=&amp;#39;_blank&amp;#39;&amp;gt;
    {parts[0]}
&amp;lt;/a&amp;gt;
```&lt;/p&gt;
&lt;p&gt;The annotation value is split on `|`. `parts[0]` becomes the visible link label; `parts[1]` becomes the `href`. **No call to `isValidURL()` is made**, unlike the protected `ApplicationURLs` component (`application-urls.tsx:72,80`) which does validate URLs and blocks `javascript:`. The `target=&amp;#39;_blank&amp;#39;` opens a new tab that inherits the ArgoCD origin, giving the injected script same-origin fetch access to all ArgoCD APIs using the victim&amp;#39;s authenticated session (credentialed `fetch()` calls).&lt;/p&gt;
&lt;p&gt;**Root cause:** React 16.x does not block `javascript…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h98r-wv3h-fr38</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1566 — Argo CD: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1566</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Argo CD ausnutzen, um Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen, wodurch potenziell Administratorrechte erlangt werden können.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Argo CD ausnutzen, um Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen, wodurch potenziell Administratorrechte erlangt werden können.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1566</guid>
    </item>
  </channel>
</rss>
