Preliminary research
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
Cloudflare Code Mode runs model-written code in workerd, the V8-isolate runtime that also provides tenant isolation for Cloudflare Workers, so untrusted code shares a single process. The research reports five memory-safety defects in workerd's C++ glue layer and two end-to-end attacks: an out-of-bounds read in URLPattern that reaches another tenant's secrets on the shared heap, and a use-after-free in node:zlib that turns a prompt injection into native code execution on the host.
Record
- Researcher
- Yarden Porat
- Published by
- Check Point Research
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Yarden Porat, first published at the original source. Preserved copies are kept so the citation survives its host.