PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-11325 Cloudflare CVE debrief

A remote code execution issue exists in the archived cloudflare/pages-action repository, specifically in src/index.ts, which can be exploited under certain GitHub Actions workflow configurations. This could lead to exposure of workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN. The repository has been deprecated since 2024 and will not receive further updates or security patches. Users of cloudflare/pages-action, especially those with workflows configured in a way that could expose sensitive information, should migrate to cloudflare/wrangler-action before the repository's scheduled removal on 2026-09-18 to prevent potential CI disruptions and security risks. Consumers who have already migrated are not affected.

Vendor
Cloudflare
Product
https://github.com/cloudflare/pages-action
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-08-28
Advisory published
2026-08-12
Advisory updated
2026-08-28

Who should care

Users of cloudflare/pages-action, especially those with workflows configured in a way that could expose sensitive information, should migrate to cloudflare/wrangler-action before the repository's scheduled removal on 2026-09-18 to prevent potential CI disruptions and security risks. This includes operators, platform administrators, vulnerability management teams, and security teams who may be impacted by the remote code execution issue.

Technical summary

A remote code execution issue exists in the archived cloudflare/pages-action repository, specifically in src/index.ts, which can be exploited under certain GitHub Actions workflow configurations. This could lead to exposure of workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN. The repository has been deprecated since 2024 and will not receive further updates or security patches. To remediate this issue, we recommend migrating to cloudflare/wrangler-action immediately. Consumers who have already migrated are not affected. The cloudflare/pages-action repository will be removed on 2026-09-18. Consumers must complete migration before 18th September to avoid CI disruption.

Defensive priority

Migrate workflows using cloudflare/pages-action to cloudflare/wrangler-action before 2026-09-18 to avoid CI disruption due to a remote code execution issue.

Recommended defensive actions

  • Immediately migrate all workflows using cloudflare/pages-action to cloudflare/wrangler-action.
  • Refer to the wrangler-action README for equivalent step configuration and migration guidance.
  • Verify migration completion before 2026-09-18 to avoid CI disruption.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

Cloudflare was notified of vulnerabilities in an archived repository, including a remote code execution issue in src/index.ts. Successful exploitation may expose workflow secrets. The repository has been deprecated since 2024 and will not receive patches. Evidence is limited, and defenders should verify migration completion before 2026-09-18 to avoid CI disruption.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-11325 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-11325

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-11325 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11325

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.