CVE-2026-11325General

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to `cloudflare/wrangler-action` immediately. Consumers who have already migrated are not affected. Sunset Date The cloudflare/pages-action repository will be removed on 2026-09-18. Consumers must complete migration before 18th September to avoid CI disruption. Affected Versions All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag. Patched Versions None. This repository will not receive further updates, including security patches. Resolution / Migration Path Migrate all workflows using cloudflare/pages-action to `cloudflare/wrangler-action` before 2026-09-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance. Credit Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare's HackerOne program that informe

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-1104

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-12: 3Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-12: 208-12
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Jaime Medina@itsJaimeMedina
    General

    Every published version of Cloudflare's discontinued pages-action remains vulnerable to CVE-2026-11325. This CVE does not identify a vulnerability in the Cloudflare Pages platform itself. Cloudflare will not patch the old action. The RCE is reachable only in certain GitHub Actions configurations, which Cloudflare has not identified publicly. Successful exploitation may expose CLOUDFLARE_API_TOKEN and GITHUB_TOKEN, but active exploitation has not been established. Search workflows for cloudflare/pages-action and migrate to cloudflare/wrangler-action. Consumers already using wrangler-action are not affected by this CVE. If an untrusted workflow may have run, review its logs and rotate exposed tokens. The migration is not a drop-in version bump, so compare the YAML and deployment outputs before merging.

    Post summary

    CVE‑2026‑11325 remains exploitable via RCE in Cloudflare pages-action across all releases; Cloudflare will not patch, but users should review logs, rotate tokens, and migrate to wrangler-action for mitigation.

    10000121
    853 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - Cloudflare pages-action GitHub Actions RCE via Workflow Config Injection (CVE-2026-11325) cloudflare/pages-action executes attacker-influenced inputs in src/index.ts under certain workflow configurations, enabling remote code execution in the runner. Successful exploitation can exfiltrate workflow secrets (e.g., CLOUDFLARE_API_TOKEN, GITHUB_TOKEN) and pivot to Cloudflare account compromise. Deprecated/archived action; no fix expected. 👉Affected: cloudflare/pages-action (all versions)

    Post summary

    Cloudflare pages-action GitHub Action contains a high‑severity RCE vulnerability (CVE-2026-11325) that allows attacker‑controlled inputs to execute arbitrary code, exfiltrate secrets, and potentially compromise a Cloudflare account; no fix is available.

    0001093
    288 followersView on X
  • Jaime Medina@itsJaimeMedina
    General

    Cloudflare's CVE record, archived pages-action repository and supported wrangler-action replacement: https://cveawg.mitre.org/api/cve/CVE-2026-11325 https://github.com/cloudflare/pages-action https://github.com/cloudflare/wrangler-action

    Post summary

    The post simply lists links to a CVE record and related GitHub Action repositories, offering no detailed information, PoC, exploit, patch, or active exploitation evidence.

    0000040
    853 followersView on X

Explore more