{"id":"CVE-2026-45738","summary":"Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation","details":"Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/src/app/applications/components/application-summary/application-summary.tsx in the Summary tab URLs section as anchor href values without URL validation, allowing javascript: execution in a higher-privileged user's authenticated Argo CD origin session. This issue is fixed in versions 3.2.12, 3.3.10, and 3.4.2.","aliases":["BIT-argo-cd-2026-45738","GHSA-h98r-wv3h-fr38","GO-2026-5418"],"modified":"2026-07-21T09:11:39.697361383Z","published":"2026-07-15T19:54:51.634Z","related":["CGA-w4hj-m326-gghh"],"database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45738.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v3.2.12"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v3.3.10"},{"type":"WEB","url":"https://github.com/argoproj/argo-cd/releases/tag/v3.4.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45738.json"},{"type":"ADVISORY","url":"https://github.com/argoproj/argo-cd/security/advisories/GHSA-h98r-wv3h-fr38"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45738"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/00f83c41dcfd879f34f8e0248c860d704b41cf0f"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/35ea43c537d6e8948e67f347317fc4f88b325122"},{"type":"FIX","url":"https://github.com/argoproj/argo-cd/commit/c8df5ff7acc403adcee1256da5d87081cd52f0a6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/argoproj/argo-cd","events":[{"introduced":"0"},{"fixed":"1966269fdc1c334a7769bd50341cf4d53490142d"},{"introduced":"fd6b7d5b3cba5e7aa7ad400b0fb905a81018a77b"},{"fixed":"4e8d8b5d05451d76412b36122d6803a90b4f406e"},{"introduced":"f082e49f6cea81ac91b620216cbe90311cafa2d4"},{"fixed":"0dc6b1b57dd5bb925d5b03c3d09419ab9fb4225e"},{"fixed":"00f83c41dcfd879f34f8e0248c860d704b41cf0f"},{"fixed":"35ea43c537d6e8948e67f347317fc4f88b325122"},{"fixed":"c8df5ff7acc403adcee1256da5d87081cd52f0a6"}],"database_specific":{"cpe":"cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.2.12"},{"introduced":"3.3.0"},{"fixed":"3.3.10"},{"introduced":"3.4.0"},{"fixed":"3.4.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v3.4.1","v3.4.0","v3.2.11","v3.3.9","v3.2.10","v3.3.8","v3.3.7","v3.2.9","v3.2.8","v3.3.6","v3.3.5","v3.3.4","v3.3.3","v3.3.2","v3.2.7","v3.3.1","v3.2.6","v3.3.0","v3.2.5","v3.2.4","stable","v3.2.3","v3.2.2","v3.2.1","v3.2.0","v3.2.0-rc4","v3.2.0-rc3","v3.2.0-rc2","v3.2.0-rc1","v0.8.0","v0.7.1","v0.7.0","v0.6.1","v0.6.0","v0.5.2","v0.5.1","v0.5.0","v0.4.5","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4.0","v0.4.0-alpha1","v0.3.3","v0.3.2","v0.3.1","v0.3.0","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45738.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"}]}