CVE-2026-11325: cloudflare/pages-action is deprecated — migration required by September 18th, 2026

Published Aug 12, 2026
·
Updated

Description

Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in src/index.ts reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLAREAPITOKEN and GITHUBTOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to cloudflare/wrangler-action immediately. Consumers who have already migrated are not affected.

Sunset Date

The cloudflare/pages-action repository will be removed on 2026-09-07. Consumers must complete migration before 7th September to avoid CI disruption.

Affected Versions

All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag.

Patched Versions

None. This repository will not receive further updates, including security patches.

Resolution / Migration Path Migrate all workflows using cloudflare/pages-action to cloudflare/wrangler-action before 2026-07-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance.

Credit

Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare's HackerOne program that informe

Other sources

Description

Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in src/index.ts reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLAREAPITOKEN and GITHUBTOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to cloudflare/wrangler-action immediately. Consumers who have already migrated are not affected.

Sunset Date

The cloudflare/pages-action repository will be removed on 2026-09-18. Consumers must complete migration before 18th September to avoid CI disruption.

Affected Versions

All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag.

Patched Versions

None. This repository will not receive further updates, including security patches.

Resolution / Migration Path Migrate all workflows using cloudflare/pages-action to cloudflare/wrangler-action before 2026-09-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance.

Credit

Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare's HackerOne program that informe

NVD

Affected Software

1 affected component
cloudflare/pages-action=

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    For every GitHub Actions workflow that uses `cloudflare/pages-action`, replace it with `cloudflare/wrangler-action` using the equivalent step configuration from the `cloudflare/wrangler-action` README migration guidance. Do this before 2026-07-18 (CI disruption window) and no later than 2026-09-18.

    GitHub Actions workflows using `cloudflare/pages-action` action reference (replace with `cloudflare/wrangler-action`) = Migrate all workflows from `cloudflare/pages-action` to `cloudflare/wrangler-action` before 2026-09-18 (and before 2026-07-18 to avoid CI disruption)
  2. Operational

    Assume workflow secrets (e.g., `CLOUDFLARE_API_TOKEN` and `GITHUB_TOKEN`) could be exposed if exploitation occurred; rotate any potentially exposed secrets after migration.

Event History

Aug 12, 2026
CVE Published
via MITRE·11:31 AM
Data Sourced
via MITRE·11:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-11325?

The severity of CVE-2026-11325 is high, with a CVSS score of 8.8.

2

How do I fix CVE-2026-11325?

To fix CVE-2026-11325, migrate away from the deprecated cloudflare/pages-action by the deadline of September 18th, 2026.

3

What kind of vulnerability is CVE-2026-11325?

CVE-2026-11325 is an OS Command Injection vulnerability that may allow remote code execution.

4

What vulnerabilities does CVE-2026-11325 expose?

CVE-2026-11325 may expose workflow secrets stored in GitHub Actions configurations.

5

When was CVE-2026-11325 published?

CVE-2026-11325 was published on August 12th, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203