
Every published version of Cloudflare's discontinued pages-action remains vulnerable to CVE-2026-11325. This CVE does not identify a vulnerability in the Cloudflare Pages platform itself. Cloudflare will not patch the old action. The RCE is reachable only in certain GitHub Actions configurations, which Cloudflare has not identified publicly. Successful exploitation may expose CLOUDFLARE_API_TOKEN and GITHUB_TOKEN, but active exploitation has not been established. Search workflows for cloudflare/pages-action and migrate to cloudflare/wrangler-action. Consumers already using wrangler-action are not affected by this CVE. If an untrusted workflow may have run, review its logs and rotate exposed tokens. The migration is not a drop-in version bump, so compare the YAML and deployment outputs before merging.
Post summary
CVE‑2026‑11325 remains exploitable via RCE in Cloudflare pages-action across all releases; Cloudflare will not patch, but users should review logs, rotate tokens, and migrate to wrangler-action for mitigation.

