CYBERSECURITYTRACKER
TRACKING7,256 stories in this site build1,517 vulnerability news stories in this site build
Permanent story citation

When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4051

As cited

Copy frozen at (site build).

ai security

When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

Check Point Research identified five memory-corruption vulnerabilities in workerd, the open-source runtime underlying Cloudflare Code Mode and Cloudflare Workers, including two rated Critical. The flaws enable two end-to-end attacks: cross-tenant heap reads allowing one worker to access another tenant's secrets, and sandbox escape from Code Mode through prompt injection and use-after-free bugs. Cloudflare has patched its managed Workers environment and released a fixed version for self-hosted deployments.

Why it matters: Developers and security teams running Cloudflare Workers or self-hosted Code Mode deployments must patch to workerd v1.20260619.1 immediately, as the vulnerabilities expose multi-tenant isolation failures and allow unauthorized access to secrets and host code execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

Check Point Research identified five memory-corruption vulnerabilities in workerd, the open-source runtime underlying Cloudflare Code Mode and Cloudflare Workers, including two rated Critical. The flaws enable two end-to-end attacks: cross-tenant heap reads allowing one worker to access another tenant's secrets, and sandbox escape from Code Mode through prompt injection and use-after-free bugs. Cloudflare has patched its managed Workers environment and released a fixed version for self-hosted deployments.

Why it matters: Developers and security teams running Cloudflare Workers or self-hosted Code Mode deployments must patch to workerd v1.20260619.1 immediately, as the vulnerabilities expose multi-tenant isolation failures and allow unauthorized access to secrets and host code execution.

VendorsGoogleCheck PointCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary