Researchers reported a chain of vulnerabilities in Cloudflare Pages build infrastructure that enabled command injection through user-controlled build settings, exposing sensitive pipeline variables including a GitHub private key for the Pages integration application and Cloudflare API credentials. The key reportedly carried read/write access to repositories for 18,290 users that had authorized the app. Subsequent findings included a world-writable binary, PATH hijacking, Azure DevOps variable injection, and passwordless sudo for the pipeline user; from a container, accessible Docker socket access allegedly allowed creation of a privileged container and recovery of Azure DevOps tokens used to enumerate Pages projects and build history.
After Cloudflare re-architected the environment around GKE and gVisor, researchers found that build containers could still reach Kubernetes host services. An unauthenticated kubelet API on TCP port 10255 exposed /pods data, including pod environment variables such as GIT_CREDS; scanning the 10.124.0.0/16 range identified multiple similarly exposed hosts, creating potential cross-tenant credential exposure. Cloudflare reportedly remediated the command-injection issue within two days and later implemented network isolation to prevent pod-to-host communication, an essential control where Kubernetes NetworkPolicy-capable networking is used to restrict L3/L4 ingress and egress paths.

Trace attribution and downstream blast radius.
9 events from the most recent confirmed update back to the earliest known activity.
Cloudflare promptly remediated the Cloudflare Pages kubelet exposure after disclosure. The reported mitigation implemented network isolation, with prevention of pod-to-host communication identified as the more comprehensive control.
Scanning the 10.124.0.0/16 range found multiple hosts exposing equivalent unauthenticated kubelet data. The researchers reported this could allow a tenant build to retrieve Git credentials associated with other users or organizations.
While testing Cloudflare Pages' GKE and gVisor-based build environment, researchers found that build containers could reach host services, including an unauthenticated kubelet API on TCP port 10255. Its /pods endpoint exposed pod specifications and environment variables, including GIT_CREDS.
From root in the Docker-based build container, researchers found an accessible /var/run/docker.sock and used it to create a privileged container with host filesystem, process, network, and device access. They reported recovering Azure DevOps instance tokens from the escaped environment and using them to enumerate Pages project users and build-run history.
Researchers reported that a Cloudflare Pages project build-command setting could inject an Azure DevOps Pipelines task.setvariable command, causing a repository-hosted reverse shell to run as the AzureDevOps pipeline user.
Cloudflare applied fixes to previously reported vulnerabilities in its Cloudflare Pages build-orchestration code, according to the researchers.
After the command-injection fix, researchers found that pages-metadata-generator was world-writable and that attacker-controlled directories persisted in PATH. They reported that these conditions could execute code as the higher-privileged AzDevOps account, which had passwordless sudo access to root within the build container.
Cloudflare remediated the initially reported Cloudflare Pages command-injection issue within two days, according to the researchers.
Assetnote researchers identified command-injection flaws in the Cloudflare Pages CLONE_REPO and PUBLISH_ASSETS workflow stages through user-controlled root-directory and output-directory settings. The flaws enabled execution in pipeline contexts containing sensitive environment variables, including a GitHub integration private key and Cloudflare API tokens.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourceslcyber.io
Open sourceslcyber.io
Open sourcekubernetes.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.