Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
YouTube Security VideosOpenAI: “It Blew Me Away” | Box’s First Look at GPT-6 Astra(21.09.2026 um 18:13 Uhr)
YouTube Security VideosGoogle Ads: Win the holiday season in 90 seconds | Rethink Retail 2026(21.09.2026 um 18:13 Uhr)
YouTube Security VideosPC-WELT: 5 crazy Sitzpositionen, die jeder Gamer kennt 😀(21.09.2026 um 18:52 Uhr)
Videos & KonferenzenMariaDB Foundation: The Fork Series #1 - The Future of Databases(21.09.2026 um 19:18 Uhr)
Videos & KonferenzenPC-WELT: 5 crazy Sitzpositionen, die jeder Gamer kennt 😀(21.09.2026 um 18:52 Uhr)
Unix & Linux ServerSecurity: Denial of Service in Memcached (Ubuntu)(21.09.2026 um 19:21 Uhr)
YouTube Security VideosOpenAI: “It Blew Me Away” | Box’s First Look at GPT-6 Astra(21.09.2026 um 18:13 Uhr)
YouTube Security VideosGoogle Ads: Win the holiday season in 90 seconds | Rethink Retail 2026(21.09.2026 um 18:13 Uhr)
YouTube Security VideosPC-WELT: 5 crazy Sitzpositionen, die jeder Gamer kennt 😀(21.09.2026 um 18:52 Uhr)
Videos & KonferenzenMariaDB Foundation: The Fork Series #1 - The Future of Databases(21.09.2026 um 19:18 Uhr)
Videos & KonferenzenPC-WELT: 5 crazy Sitzpositionen, die jeder Gamer kennt 😀(21.09.2026 um 18:52 Uhr)
Unix & Linux ServerSecurity: Denial of Service in Memcached (Ubuntu)(21.09.2026 um 19:21 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

CVE-2026-1721: CVE-2026-1721: When JSON.stringify() Betrays You in Cloudflare Agents

CVE-2026-1721: When JSON.stringify() Betrays You in Cloudflare Agents Vulnerability ID: CVE-2026-1721 CVSS Score: 6.2 Published: 2026-02-13 A classic Reflected Cross-Site Scripting (XSS) vulnerability found in the Cloudflare Agents AI…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




CVE-2026-1721: When JSON.stringify() Betrays You in Cloudflare Agents




Vulnerability ID: CVE-2026-1721

CVSS Score: 6.2

Published: 2026-02-13




A classic Reflected Cross-Site Scripting (XSS) vulnerability found in the Cloudflare Agents AI Playground. The flaw stems from a misunderstanding of how browsers parse script tags within inline HTML, allowing attackers to break out of a JSON string context and execute arbitrary JavaScript. This exposes sensitive LLM chat history and connected Model Context Protocol (MCP) servers to unauthorized access.






TL;DR



Reflected XSS in Cloudflare Agents AI Playground (< 0.3.10) via OAuth callbacks. Developers used JSON.stringify inside a <script> block, assuming it was safe. It wasn't. Attackers can inject </script> to break out and steal chat logs or hijack MCP sessions.









⚠️ Exploit Status: POC






Technical Details





  • Vulnerability Type: Reflected Cross-Site Scripting (XSS)


  • CWE ID: CWE-79


  • CVSS Score: 6.2 (Medium)


  • Attack Vector: Network (Reflected)


  • Exploit Status: PoC Available


  • Impact: Session Hijacking, Data Exfiltration






Affected Systems




  • Cloudflare Agents AI Playground

  • Applications using agents package < 0.3.10

  • Custom OAuth callback implementations based on the vulnerable example


  • Cloudflare Agents: < 0.3.10 (Fixed in: 0.3.10)






Code Analysis






Commit: 3f490d0



Fix XSS in OAuth callback handler by removing error reflection




- const safeError = JSON.stringify(result.authError);
- return new Response(`<script>alert(${safeError})</script>`)
+ return new Response(`<script>window.close()</script>`)









Mitigation Strategies




  • Avoid inline scripts reflecting user input.

  • Use 'serialize-javascript' instead of 'JSON.stringify' for HTML contexts.

  • Implement Content Security Policy (CSP) to block inline scripts.



Remediation Steps:




  1. Upgrade the agents npm package to version 0.3.10 or later.

  2. Audit any custom OAuth callback handlers for JSON.stringify usage inside Response bodies.

  3. Verify that error and error_description parameters are never rendered raw.






References








Read the full report for CVE-2026-1721 on our website for more details including interactive diagrams and full exploit analysis.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten CVE-2026-1721: CVE-2026-1721: When JSON.stringify() Betrays You in Cloudflare Agents

Thematisch verwandte Begriffe: CVE20261721, When, JSONstringify, Betrays · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-82412 | ntopng is a web-based network traffic monitoring application. Prior to 6…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick