CVE-2026-45738
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd
7.3
HIGH
CVSS 3.1
Description
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation in github.com/argoproj/argo-cd
How to fix CVE-2026-45738
To remediate CVE-2026-45738, upgrade the affected package to a fixed version below.
- Go/github.com/argoproj/argo-cd—no fix listed
- Go/github.com/argoproj/argo-cd—no fix listed
- —no fix listed
- —no fix listed
- —upgrade to 3.2.12 or later
- —upgrade to 3.2.12 or later
Is CVE-2026-45738 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-45738.
Affected packages (6)
- from 0, <= 1.8.7
- from 0
- from 0, <= 2.14.21
- from 0
- from 0, < 3.2.12
- from 0, < 3.2.12, >= 3.3.0-rc1, < 3.3.10, >= 3.4.0-rc1, < 3.4.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |