← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 6, 2026 · 22:20via Check Point Research

When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

Brief

By Yarden Porat, Check Point Research

Key Points

  • Check Point Research analyzed Cloudflare Code Mode, a technique that changes how AI agents use MCP by turning tools into a TypeScript API the model can write code against.
  • The research uncovered five vulnerabilities in workerd, the open-source runtime behind Code Mode and Cloudflare Workers. Two were rated Critical by Cloudflare.
  • The blast radius is broad: by Cloudflare’s own numbers, Workers is built by  millions of developers ,[1] serves  millions of requests per second ,[2] and carries  more than 10% of all traffic on Cloudflare’s network .[3]
  • Because workerd underpins both Code Mode sandboxes and Workers tenant isolation, the findings create sandbox-escape and cross-tenant exposure risk.
  • Cloudflare’s managed Workers environment has been fixed in production.
Read more on Check Point Research