Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-11325: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') in Cloudflare https://github.com/cloudflare/pages-action

0
High
VulnerabilityCVE-2026-11325cvecve-2026-11325cwe-78cwe-1104
Published: 08/12/2026 (08/12/2026, 11:31:15 UTC)
Source: CVE Database V5
Vendor/Project: Cloudflare
Product: https://github.com/cloudflare/pages-action

Description

Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to `cloudflare/wrangler-action` immediately. Consumers who have already migrated are not affected. Sunset Date The cloudflare/pages-action repository will be removed on 2026-09-18. Consumers must complete migration before 18th September to avoid CI disruption. Affected Versions All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag. Patched Versions None. This repository will not receive further updates, including security patches. Resolution / Migration Path Migrate all workflows using cloudflare/pages-action to `cloudflare/wrangler-action` before 2026-09-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance. Credit Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare's HackerOne program that informe

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

GitHub Actionsmore threats →cve
https://github.com/cloudflare/pages-action
pkg:github/https://github.com/cloudflare/pages-action

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 11:56:10 UTC

Technical Analysis

Cloudflare was notified of an OS command injection vulnerability (CWE-78) in the archived cloudflare/pages-action GitHub repository, specifically in src/index.ts, which can be exploited through certain GitHub Actions workflows. Successful exploitation may lead to remote code execution and exposure of sensitive tokens used in workflows. Since the repository is deprecated and scheduled for removal, Cloudflare will not issue patches. Users are advised to migrate to cloudflare/wrangler-action before July 18, 2026, to avoid disruption and mitigate the vulnerability.

Potential Impact

Exploitation of this vulnerability can result in remote code execution within GitHub Actions workflows and exposure of sensitive secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN. This could lead to unauthorized access and control over workflows and associated resources. No known exploits are reported in the wild at this time.

Mitigation Recommendations

Cloudflare will not provide patches for this vulnerability as the repository is deprecated. Users must migrate all workflows from cloudflare/pages-action to cloudflare/wrangler-action before July 18, 2026, to mitigate the risk. This migration is the recommended and only remediation path. Users who have already migrated are not affected.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
cloudflare
Date Reserved
2026-06-04T23:49:45.491Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null
Is Cloud Service
true

Threat ID: 6a7c5c0ebf8831d5397997e7

Added to database: 08/12/2026, 11:42:06 UTC

Last enriched: 08/12/2026, 11:56:10 UTC

Last updated: 08/12/2026, 12:16:02 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses