Preliminary research
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Cloudflare Code Mode runs model-written code in workerd, the V8-isolate runtime that also provides tenant isolation for Cloudflare Workers, so untrusted code shares a single process. The research reports five memory-safety defects in workerd's C++ glue layer and two end-to-end attacks: an out-of-bounds read in URLPattern that reaches another tenant's secrets on the shared heap, and a use-after-free in node:zlib that turns a prompt injection into native code execution on the host.
Record
- Researcher
- Yarden Porat
- Published by
- Check Point Research
- Date
- Topic
- Server
In the archive
Related sources
- When Agentic Glue Melts: Exploiting Cloudflare Code Mode & Workers (Slides) Whitepaper
- PoCs Repository
Tags
This page is the archive's own catalogue record. The research is the work of Yarden Porat, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .