CVE-2026-11325

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
12/08/2026
Last modified:
12/08/2026

Description

Description<br /> <br /> <br /> <br /> Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to `cloudflare/wrangler-action` immediately. Consumers who have already migrated are not affected.<br /> <br /> <br /> <br /> <br /> Sunset Date<br /> <br /> <br /> <br /> The cloudflare/pages-action repository will be removed on 2026-09-18. Consumers must complete migration before 18th September to avoid CI disruption.<br /> <br /> <br /> <br /> <br /> Affected Versions<br /> <br /> <br /> <br /> All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag.<br /> <br /> <br /> <br /> <br /> Patched Versions<br /> <br /> <br /> <br /> None. This repository will not receive further updates, including security patches.<br /> <br /> <br /> <br /> <br /> Resolution / Migration Path<br /> Migrate all workflows using cloudflare/pages-action to `cloudflare/wrangler-action` before 2026-09-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance.<br /> <br /> <br /> <br /> <br /> Credit<br /> <br /> <br /> <br /> Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare&amp;#39;s HackerOne program that informe

References to Advisories, Solutions, and Tools