When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

2026-08-10T08:52:18Z58549a7106813dc441ab7ce9e3dbc9279d978443890098d91c84a0d03a8f1277
AI securityC++C2 frameworkCavern ManticoreCloudflareCloudflare WorkersCode ModeIran-linked APTLangGraphSQL injectionV8browser-only ransomwareclipboard hijackercontainer escapecryptocurrencymemory corruptionransomwareremote code executionsandbox escapesupply-chain attackthreat intelligenceworkerd

What happened

Check Point Research reports five memory-corruption vulnerabilities in workerd, the native C++ runtime underlying Cloudflare Code Mode and Workers. The runtime relies on V8 for in-process sandboxing, so successful exploitation could enable sandbox escape, unauthorized access to host or tenant resources, and potentially remote code execution depending on deployment context. The document also covers active threats including Iran-linked Cavern Manticore, browser-only ransomware, crypto clipboard hijacking, AI-agent framework exploitation, and supply-chain attacks; however, the primary security-re

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
58549a7106813dc441ab7ce9e3dbc9279d978443890098d91c84a0d03a8f1277
Enrichment time
2026-08-10T08:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.