CVE-2026-1721Disclosure

LOWCVSS 6.2 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The `error_description` query parameter was directly interpolated into an HTML script tag without proper escaping, allowing attackers to execute arbitrary JavaScript in the context of the victim's session. Root cause The OAuth callback handler in `site/ai-playground/src/server.ts` directly interpolated the `authError` value, sourced from the `error_description` query parameter, into an inline `<script>` tag. Impact An attacker could craft a malicious link that, when clicked by a victim, would: * Steal user chat message history - Access all LLM interactions stored in the user's session. * Access connected MCP Servers - Interact with any MCP servers connected to the victim's session (public or authenticated/private), potentially allowing the attacker to perform actions on the victim's behalf Mitigation: * PR:  https://github.com/cloudflare/agents/pull/841 https://github.com/cloudflare/agents/pull/841 * Agents-sdk users should upgrade to [email protected] * Developers using configureOAuthCallback with custom error handling in their own applications should ensure all user-controlled input is escaped before interpolation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 3 mentions (2026-02-13); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-13: 3Mentions · 2026-02-14: 1Mentions · 2026-02-27: 1Mentions · 2026-05-06: 1Technical Details · 2026-02-13: 3Technical Details · 2026-02-14: 1Technical Details · 2026-02-27: 1Technical Details · 2026-05-06: 102-1302-1402-2705-06
Signal classification1 categories
Disclosure
6100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-133
Disclosure3
2026-02-141
Disclosure1
2026-02-271
Disclosure1
2026-05-061
Disclosure1
Full discourse6 posts
  • Prateek Tomar@TomarPrateek23
    Disclosure

    Just published: Critical Analysis CVE-2026-1721 - Summary A Reflected Cross-Site Scripting.... Practical security guidance from the trenches. Read more: https://threatops.tech/blog/critical-analysis-cve-2026-1721-summary-a-reflected-cross-site-scripting-xss-vulnerabilit-february

    Post summary

    The post announces a blog that provides a critical analysis of CVE‑2026‑1721, identifying it as a reflected XSS vulnerability and offering practical guidance.

    0001151
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1721 Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The `error_description` query parameter was … https://www.cve.org/CVERecord?id=CVE-2026-1721

    Post summary

    The text discloses a reflected XSS vulnerability in AI Playground’s OAuth callback handler, specifying the affected parameter, but does not provide PoC, exploit, or mitigation details.

    00020326
    56.5K followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-1721: Critical XSS in Cloudflare AI Playground OAuth Handler Threatens MCP Server Access https://moltx.io/articles/db93f35a-fbf2-4202-a632-08ee65190744

    Post summary

    The article announces CVE‑2026‑1721 as a critical cross‑site scripting flaw in Cloudflare’s AI Playground OAuth handler that could jeopardize MCP server access, but it provides no PoC, exploit code, or evidence of active exploitation.

    0001081
    5 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-1721: CVE-2026-1721: When JSON.stringify() Betrays You in Cloudflare Agents A classic Reflected Cross-Site Scripting (XSS) vulnerability found in the Cloudflare Agents AI Playground. The flaw stems from a misunderstanding of how browsers pars... https://cvereports.com/reports/CVE-2026-1721

    Post summary

    The report outlines a classic reflected XSS flaw in Cloudflare Agents AI Playground, detailing its type but providing no PoC, exploit code, or patch information.

    0000077
    26 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1721 📊 Severity: 6.2 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1721 #CVE-2026-1721 #CVE #Medium #CyberSecurity #InfoSec https://t.co/pHeHOBlsV6

    Post summary

    A new CVE (2026‑1721) is announced with moderate severity (6.2) affecting unspecified products; no PoC, exploit, active exploitation, or patch information is provided.

    0000037
    57 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1721 Reflected XSS in AI Playground OAuth Callback Enables Arbitrary JavaScript Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1721

    Post summary

    The passage announces a reflected XSS vulnerability in AI Playground’s OAuth callback that allows arbitrary JavaScript execution, but offers no PoC, exploit, or patch information.

    0000033
    4.0K followersView on X

Explore more