CVE-2026-11325: cloudflare/pages-action is deprecated — migration required by September 18th, 2026
Description
Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in src/index.ts reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLAREAPITOKEN and GITHUBTOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to cloudflare/wrangler-action immediately. Consumers who have already migrated are not affected.
Sunset Date
The cloudflare/pages-action repository will be removed on 2026-09-07. Consumers must complete migration before 7th September to avoid CI disruption.
Affected Versions
All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag.
Patched Versions
None. This repository will not receive further updates, including security patches.
Resolution / Migration Path Migrate all workflows using cloudflare/pages-action to cloudflare/wrangler-action before 2026-07-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance.
Credit
Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare's HackerOne program that informe
Other sources
Description
Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in src/index.ts reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLAREAPITOKEN and GITHUBTOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to cloudflare/wrangler-action immediately. Consumers who have already migrated are not affected.
Sunset Date
The cloudflare/pages-action repository will be removed on 2026-09-18. Consumers must complete migration before 18th September to avoid CI disruption.
Affected Versions
All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag.
Patched Versions
None. This repository will not receive further updates, including security patches.
Resolution / Migration Path Migrate all workflows using cloudflare/pages-action to cloudflare/wrangler-action before 2026-09-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance.
Credit
Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare's HackerOne program that informe
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
For every GitHub Actions workflow that uses `cloudflare/pages-action`, replace it with `cloudflare/wrangler-action` using the equivalent step configuration from the `cloudflare/wrangler-action` README migration guidance. Do this before 2026-07-18 (CI disruption window) and no later than 2026-09-18.
GitHub Actions workflows using `cloudflare/pages-action` action reference (replace with `cloudflare/wrangler-action`) = Migrate all workflows from `cloudflare/pages-action` to `cloudflare/wrangler-action` before 2026-09-18 (and before 2026-07-18 to avoid CI disruption) - Operational
Assume workflow secrets (e.g., `CLOUDFLARE_API_TOKEN` and `GITHUB_TOKEN`) could be exposed if exploitation occurred; rotate any potentially exposed secrets after migration.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11325?
The severity of CVE-2026-11325 is high, with a CVSS score of 8.8.
How do I fix CVE-2026-11325?
To fix CVE-2026-11325, migrate away from the deprecated cloudflare/pages-action by the deadline of September 18th, 2026.
What kind of vulnerability is CVE-2026-11325?
CVE-2026-11325 is an OS Command Injection vulnerability that may allow remote code execution.
What vulnerabilities does CVE-2026-11325 expose?
CVE-2026-11325 may expose workflow secrets stored in GitHub Actions configurations.
When was CVE-2026-11325 published?
CVE-2026-11325 was published on August 12th, 2026.