CVE-2023-7079
MEDIUMCloudflare Wrangler 3.9.0-3.18.9 - Unauthenticated Arbitrary File Read via Dev Server
Title source: llmDescription
Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessible over the local network. An attacker that could trick any user on the local network into opening a malicious website could also read any file.
References (3)
Core 3
Core References
Patch, Third Party Advisory
https://github.com/cloudflare/workers-sdk/security/advisories/GHSA-cfph-4qqh-w828
Scores
CVSS v3
6.4
EPSS
0.0007
EPSS Percentile
21.7%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Details
CWE
CWE-287
Status
published
Products (2)
cloudflare/wrangler
3.9.0 - 3.19.0
npm/wrangler
3.9.0 - 3.19.0npm
Published
Dec 29, 2023
Tracked Since
Feb 18, 2026