MEDIUMnpm
GHSA-cvhv-6xm6-c3v4· CVE-2026-1721Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handler
Modified: 2/13/2026
package
pkg:npm/agents
Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handler
Modified: 2/13/2026
Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing
Modified: 2/22/2026
Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site
Modified: 2/13/2026