Skip to content

[GHSA-cvhv-6xm6-c3v4] Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handler#6932

Open
cai0duque wants to merge 1 commit intocai0duque/advisory-improvement-6932from
cai0duque-GHSA-cvhv-6xm6-c3v4
Open

[GHSA-cvhv-6xm6-c3v4] Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handler#6932
cai0duque wants to merge 1 commit intocai0duque/advisory-improvement-6932from
cai0duque-GHSA-cvhv-6xm6-c3v4

Conversation

@cai0duque
Copy link

Updates

  • CVSS v4

Comments
Updated CVSS 4.0 metrics for greater accuracy.

  1. Changed User Interaction (UI) to 'Passive (P)': The vulnerability is a Reflected XSS where the payload is interpolated into an inline <script> tag. Execution occurs immediately upon visiting the malicious URL (loading the page), which fits the CVSS 4.0 definition of Passive interaction better than Active.
  2. Increased Subsequent Integrity (SI) to 'High (H)': As noted in the description, the attacker can interact with connected MCP servers and perform actions on the victim's behalf, justifying a High Integrity impact.

Copilot AI review requested due to automatic review settings February 17, 2026 09:24
@github-actions github-actions bot changed the base branch from main to cai0duque/advisory-improvement-6932 February 17, 2026 09:26
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the advisory’s CVSS v4.0 vector to better reflect the reported reflected XSS behavior and downstream integrity impact.

Changes:

  • Adjusted CVSS v4.0 User Interaction (UI) from Active (A) to Passive (P)
  • Increased Subsequent Integrity (SI) from Low (L) to High (H)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant