{"id":"CVE-2026-11325","summary":"cloudflare/pages-action is deprecated — migration required by September 18th, 2026","details":"Description\n\n\n\nCloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to `cloudflare/wrangler-action` immediately. Consumers who have already migrated are not affected.\n\n\n\n\nSunset Date\n\n\n\nThe cloudflare/pages-action repository will be removed on 2026-09-18. Consumers must complete migration before 18th September to avoid CI disruption.\n\n\n\n\nAffected Versions\n\n\n\nAll published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag.\n\n\n\n\nPatched Versions\n\n\n\nNone. This repository will not receive further updates, including security patches.\n\n\n\n\nResolution / Migration Path\nMigrate all workflows using cloudflare/pages-action to `cloudflare/wrangler-action` before 2026-09-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance.\n\n\n\n\nCredit\n\n\n\nThanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare's HackerOne program that informe","modified":"2026-10-08T02:51:05.796412216Z","published":"2026-08-12T11:31:15.102Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11325.json","cna_assigner":"cloudflare","cwe_ids":["CWE-1104","CWE-78"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11325.json"},{"type":"ADVISORY","url":"https://github.com/cloudflare/wrangler-action"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11325"},{"type":"PACKAGE","url":"https://github.com/cloudflare/pages-action"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudflare/wrangler-action","events":[{"introduced":"0"},{"last_affected":"0"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0"}],"source":"AFFECTED_FIELD"}}],"versions":["0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11325.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}