
🚨 High - Argo CD Stored XSS → Admin Session Hijack (CVE-2026-45738) A stored XSS in Argo CD's application Summary tab allows a developer with application write access to inject JavaScript URIs via annotation values using the pipe-delimited "Display Text | javascript:..." format. When an administrator views the application and clicks the disguised link, arbitrary JavaScript executes in the admin's authenticated session, leading to a full takeover of the GitOps controller and every Kubernetes workload it manages. The root cause is React 16.x rendering unsanitized JavaScript hrefs, combined with missing URL validation and a permissive CSP. This high-severity flaw (CVSS 7.3) requires an authenticated, low-privilege developer and a single admin click. 👉 Affected: Argo CD < 3.2.12, < 3.3.10, < 3.4.2 | Upgrade to 3.2.12, 3.3.10, or 3.4.2
Post summary
The post describes a stored XSS in Argo CD that can hijack admin sessions and provides the vendor-specified patch releases to mitigate the flaw.
