Junglewise Threat Intelligence

CVE-2026-0933: Cloudflare Wrangler OS command injection in pages deploy

CVE-2026-0933 · Severity: medium · CVSS 4 · Published 2026-01-21

Vendors: Cloudflare.

Executive brief

Wrangler is Cloudflare's command-line tool for deploying serverless applications to Cloudflare Workers. The `wrangler pages deploy` subcommand contains a vulnerability that allows attackers to execute arbitrary shell commands if they can control the `--commit-hash` parameter. This risk is highest in CI/CD environments where this parameter is populated from external sources, potentially allowing attackers to steal credentials, modify deployed code, or compromise build infrastructure.

Technical details

The vulnerability is a command injection (CWE-78) in the `wrangler pages deploy` command. The root cause is that the `commitHash` variable, derived from the `--commit-hash` CLI argument, is interpolated directly into a shell command using template literals (e.g., `execSync(\`git show -s --format=%B ${commitHash}\`)`), allowing shell metacharacters to be interpreted. The attack vector is network-accessible in CI/CD scenarios where the commit hash comes from untrusted sources. No special privileges are required beyond the ability to provide the `--commit-hash` argument. A successful exploit enables arbitrary shell command execution on the build runner, potentially leading to credential exfiltration, artifact modification, or backdoor installation. The fix, released in Wrangler v4.59.1 and v3.114.17, uses argument arrays instead of shell string interpolation to safely pass user input to git commands.

Affected products

  • Cloudflare Wrangler >=2.0.15, 3.0.0-3.114.16, 4.0.0-4.59.0

Timeline

  • 2026-01-21: disclosed: GHSA-36p8-mvp6-cv38 published
  • 2026-01-13: patched: Fix committed; Wrangler v3.114.17 and v4.59.1 released on 2026-01-13

References