As cited
Copy frozen at (site build).
ai security
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
Check Point Research identified five memory-corruption vulnerabilities in workerd, the open-source runtime underlying Cloudflare Code Mode and Cloudflare Workers, including two rated Critical. The flaws enable two end-to-end attacks: cross-tenant heap reads allowing one worker to access another tenant's secrets, and sandbox escape from Code Mode through prompt injection and use-after-free bugs. Cloudflare has patched its managed Workers environment and released a fixed version for self-hosted deployments.
Why it matters: Developers and security teams running Cloudflare Workers or self-hosted Code Mode deployments must patch to workerd v1.20260619.1 immediately, as the vulnerabilities expose multi-tenant isolation failures and allow unauthorized access to secrets and host code execution.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
Check Point Research identified five memory-corruption vulnerabilities in workerd, the open-source runtime underlying Cloudflare Code Mode and Cloudflare Workers, including two rated Critical. The flaws enable two end-to-end attacks: cross-tenant heap reads allowing one worker to access another tenant's secrets, and sandbox escape from Code Mode through prompt injection and use-after-free bugs. Cloudflare has patched its managed Workers environment and released a fixed version for self-hosted deployments.
Why it matters: Developers and security teams running Cloudflare Workers or self-hosted Code Mode deployments must patch to workerd v1.20260619.1 immediately, as the vulnerabilities expose multi-tenant isolation failures and allow unauthorized access to secrets and host code execution.
- Source published
- First seen by Cybersecurity Tracker