Description
Description



Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to `cloudflare/wrangler-action` immediately. Consumers who have already migrated are not affected.




Sunset Date



The cloudflare/pages-action repository will be removed on 2026-09-18. Consumers must complete migration before 18th September to avoid CI disruption.




Affected Versions



All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag.




Patched Versions



None. This repository will not receive further updates, including security patches.




Resolution / Migration Path
Migrate all workflows using cloudflare/pages-action to `cloudflare/wrangler-action` before 2026-09-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance.




Credit



Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare's HackerOne program that informe
Published: 2026-08-12
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Cloudflare’s archived cloudflare/pages-action repository. A flaw in src/index.ts allows a malicious actor to execute arbitrary code when the action is invoked in a GitHub Actions workflow. Successful exploitation can expose sensitive workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN, effectively granting the attacker access to Cloudflare accounts and potentially broader systems. The issue is identified as a remote code execution problem combined with secret exposure, corresponding to the listed CWE weaknesses: CWE-1104 for exposed secrets and CWE-78 for command injection.

Affected Systems

All versions of the cloudflare/pages-action GitHub Action are affected, including every release and any workflow that pins to the v1 moving tag. This includes any project using the action in its CI configuration, regardless of the hosted repository or deployment target, as the action code is executed within the workflow runner environment.

Risk and Exploitability

The CVSS score of 8.8 classifies this flaw as a high severity vulnerability. No EPSS value is available, so the probability of exploitation cannot be quantified here, but the lack of a patch and the permission model of GitHub Actions suggest a realistic attack opportunity. The vulnerability is not listed in CISA’s KEV catalogue. Because the action repository is deprecated and will be removed on 2026‑09‑18, the only viable mitigation is to move to the actively maintained cloudflare/wrangler-action prior to that date; failure to do so will result in CI disruption and continued exposure to the flaw.

Generated by OpenCVE AI on August 13, 2026 at 01:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace every reference to cloudflare/pages-action in GitHub workflow YAML files with cloudflare/wrangler-action, following the equivalent step configuration shown in the wrangler-action README.
  • Update any pinned tags or branch references to the new action, ensuring that the action’s inputs match the original configuration so that the deployment workflow continues to function correctly.
  • After migration, validate the workflow by triggering a test deployment to confirm that it runs successfully and that no secrets are inadvertently exposed.

Generated by OpenCVE AI on August 13, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Cloudflare
Cloudflare pages-action
Vendors & Products Cloudflare
Cloudflare pages-action

Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to `cloudflare/wrangler-action` immediately. Consumers who have already migrated are not affected. Sunset Date The cloudflare/pages-action repository will be removed on 2026-09-07. Consumers must complete migration before 7th September to avoid CI disruption. Affected Versions All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag. Patched Versions None. This repository will not receive further updates, including security patches. Resolution / Migration Path Migrate all workflows using cloudflare/pages-action to `cloudflare/wrangler-action` before 2026-07-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance. Credit Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare's HackerOne program that informe Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to `cloudflare/wrangler-action` immediately. Consumers who have already migrated are not affected. Sunset Date The cloudflare/pages-action repository will be removed on 2026-09-18. Consumers must complete migration before 18th September to avoid CI disruption. Affected Versions All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag. Patched Versions None. This repository will not receive further updates, including security patches. Resolution / Migration Path Migrate all workflows using cloudflare/pages-action to `cloudflare/wrangler-action` before 2026-09-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance. Credit Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare's HackerOne program that informe

Wed, 12 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to `cloudflare/wrangler-action` immediately. Consumers who have already migrated are not affected. Sunset Date The cloudflare/pages-action repository will be removed on 2026-09-07. Consumers must complete migration before 7th September to avoid CI disruption. Affected Versions All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag. Patched Versions None. This repository will not receive further updates, including security patches. Resolution / Migration Path Migrate all workflows using cloudflare/pages-action to `cloudflare/wrangler-action` before 2026-07-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance. Credit Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare's HackerOne program that informe
Title cloudflare/pages-action is deprecated — migration required by September 18th, 2026
Weaknesses CWE-1104
CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Cloudflare Pages-action
cve-icon MITRE

Status: PUBLISHED

Assigner: cloudflare

Published:

Updated: 2026-08-12T12:06:10.745Z

Reserved: 2026-06-04T23:49:45.491Z

Link: CVE-2026-11325

cve-icon Vulnrichment

Updated: 2026-08-12T12:05:47.893Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T12:17:44.370

Modified: 2026-08-28T15:42:20.060

Link: CVE-2026-11325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:48:45Z

Weaknesses
  • CWE-1104

    Use of Unmaintained Third Party Components

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')