When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
Check Point Research identified five vulnerabilities in workerd, the open-source runtime behind Cloudflare Code Mode and Cloudflare Workers. Two of these vulnerabilities were rated critical by Cloudflare. The flaws enable sandbox escape and cross-tenant data exposure risks, affecting the isolation model that runs untrusted code in V8 isolates within a single process. Cloudflare's managed Workers environment has been fixed in production, while self-hosted workerd and Code Mode deployments require updating to version v1.20260619.1. The vulnerabilities include an out-of-bounds read allowing cross-tenant heap data access and a use-after-free leading to sandbox escape and native code execution on the host. These issues impact a widely used serverless platform that processes millions of requests per second and handles over 10% of Cloudflare's network traffic.
AI Analysis
Technical Summary
Cloudflare's workerd runtime underpins both Code Mode, a system allowing AI agents to write TypeScript code against APIs, and Cloudflare Workers, a serverless edge computing platform. Check Point Research discovered five memory corruption vulnerabilities in workerd's native C++ code, which acts as the interface between JavaScript and the runtime. Two critical vulnerabilities include: (1) an out-of-bounds read in URLPattern enabling one tenant's Worker to access another tenant's heap memory and secrets, and (2) a use-after-free triggered via node:zlib that allows sandbox escape and execution of native code on the host machine. These vulnerabilities undermine the isolation guarantees provided by V8 isolates, which are used to securely run multiple tenants' code within the same process. Cloudflare has deployed fixes in its managed Workers environment, and self-hosted deployments must upgrade to version v1.20260619.1 to mitigate these risks. Proof-of-concept exploit code was publicly released by Check Point Research.
Potential Impact
The vulnerabilities allow attackers to bypass sandbox isolation in Cloudflare Workers and Code Mode environments. This can lead to cross-tenant data leakage by reading memory from other tenants' Workers and potentially executing arbitrary native code on the host system. Given the scale of Cloudflare Workers—serving millions of requests per second and hosting millions of developers—successful exploitation could compromise sensitive data and undermine the security of multiple tenants sharing the same runtime process. The critical severity reflects the potential for broad impact and loss of tenant isolation.
Mitigation Recommendations
Cloudflare has fixed these vulnerabilities in its managed Workers environment. Operators of self-hosted workerd and Code Mode deployments should update to version v1.20260619.1 to apply the official fix. No additional mitigations are indicated or required beyond applying this update. Users should consult Cloudflare's advisory and Check Point Research's disclosures for detailed guidance.
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
Description
Check Point Research identified five vulnerabilities in workerd, the open-source runtime behind Cloudflare Code Mode and Cloudflare Workers. Two of these vulnerabilities were rated critical by Cloudflare. The flaws enable sandbox escape and cross-tenant data exposure risks, affecting the isolation model that runs untrusted code in V8 isolates within a single process. Cloudflare's managed Workers environment has been fixed in production, while self-hosted workerd and Code Mode deployments require updating to version v1.20260619.1. The vulnerabilities include an out-of-bounds read allowing cross-tenant heap data access and a use-after-free leading to sandbox escape and native code execution on the host. These issues impact a widely used serverless platform that processes millions of requests per second and handles over 10% of Cloudflare's network traffic.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cloudflare's workerd runtime underpins both Code Mode, a system allowing AI agents to write TypeScript code against APIs, and Cloudflare Workers, a serverless edge computing platform. Check Point Research discovered five memory corruption vulnerabilities in workerd's native C++ code, which acts as the interface between JavaScript and the runtime. Two critical vulnerabilities include: (1) an out-of-bounds read in URLPattern enabling one tenant's Worker to access another tenant's heap memory and secrets, and (2) a use-after-free triggered via node:zlib that allows sandbox escape and execution of native code on the host machine. These vulnerabilities undermine the isolation guarantees provided by V8 isolates, which are used to securely run multiple tenants' code within the same process. Cloudflare has deployed fixes in its managed Workers environment, and self-hosted deployments must upgrade to version v1.20260619.1 to mitigate these risks. Proof-of-concept exploit code was publicly released by Check Point Research.
Potential Impact
The vulnerabilities allow attackers to bypass sandbox isolation in Cloudflare Workers and Code Mode environments. This can lead to cross-tenant data leakage by reading memory from other tenants' Workers and potentially executing arbitrary native code on the host system. Given the scale of Cloudflare Workers—serving millions of requests per second and hosting millions of developers—successful exploitation could compromise sensitive data and undermine the security of multiple tenants sharing the same runtime process. The critical severity reflects the potential for broad impact and loss of tenant isolation.
Mitigation Recommendations
Cloudflare has fixed these vulnerabilities in its managed Workers environment. Operators of self-hosted workerd and Code Mode deployments should update to version v1.20260619.1 to apply the official fix. No additional mitigations are indicated or required beyond applying this update. Users should consult Cloudflare's advisory and Check Point Research's disclosures for detailed guidance.
Technical Details
- Classification
- {"confidence":0.71,"severitySource":"stated","classifier":"rss-v2"}
- Article Source
- {"url":"https://research.checkpoint.com/2026/when-agentic-glue-melts/","fetched":true,"fetchedAt":"2026-08-07T18:01:59.027Z","wordCount":6521}
Threat ID: 6a761d97bf8831d539d5300c
Added to database: 08/07/2026, 18:01:59 UTC
Last enriched: 08/07/2026, 18:02:10 UTC
Last updated: 08/08/2026, 01:06:03 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.