Executive Summary
Check Point Research uncovered five significant vulnerabilities in 'workerd', the open-source runtime powering Cloudflare Workers and the AI-focused 'Code Mode'. Two of these vulnerabilities were rated Critical by Cloudflare, as they allow attackers to bypass the V8 isolate boundary and memory protection keys. The findings demonstrate that native C++ 'glue' layers in language runtimes represent a significant attack surface that remains outside the protection of primary sandboxing mechanisms like the V8 'cage'.
The research specifically highlights that because workerd handles many tenants within a single process, memory corruption in the native tcmalloc heap can be weaponized for cross-tenant secret theft or complete sandbox escape to the host. While Cloudflare has patched its managed environments, self-hosted workerd deployments remain at risk unless updated to version v1.20260619.1 or later. The vulnerabilities also underscore emerging risks in agentic AI, where model-generated code can be steered to exploit these low-level runtime flaws.
