HNHacker News
TopNewBestAskShowJobs

shahartal

106 karma · joined July 14, 2013

[ my public key: https://keybase.io/jifa; my proof: https://keybase.io/jifa/sigs/1Jj0ie4kUTSYwaHK09tBCZIdEJAhAFOPH3qScdAzlXI ]
submissionscomments
shahartal··on When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
Author here (Yarden & Shahar from Check Point Research). Context on what this is and isn't:

We set out to break Cloudflare's Code Mode and ended up in workerd, the runtime underneath both Code Mode and Cloudflare Workers. Five memory-corruption bugs in workerd's native C++ "glue" (the layer that hands C++ objects to untrusted JS), two rated Critical by Cloudflare. We chained them into two end-to-end attacks: a cross-tenant heap read that swipes another Worker's secrets, and a Code Mode sandbox escape that goes from a single prompt injection to native code on the host.

The core insight: the V8 "cage" and memory-protection keys don't cover the tcmalloc native heap - and that's exactly where the glue layer allocates its objects. If the cage is your isolation story, the memory it doesn't cover is your attack surface.

Honest caveats: both full exploits were verified on self-hosted workerd, not run against Cloudflare production. The cross-tenant path should behave the same in prod since it runs entirely on the uncovered tcmalloc heap, but we didn't test it there. Cloudflare has fixed managed Workers in production; self-hosted deployments should update to workerd v1.20260619.1. No CVEs assigned or advisories issued by Cloudflare policy.

Happy to answer questions.

shahartal··on Critical vulnerability in LangChain – CVE-2025-68664
CVE-2025-68664 (langchain-core): object confusion during (de)serialization can leak secrets (and in some cases escalate further). Details and mitigations in the post.
shahartal··on Zero-day flaws in authentication, identity, authorization in HashiCorp Vault
Hey all — authors of Vault Fault here (I’m Shahar, CEO at Cyata), really appreciate all the thoughtful comments.

Just to clarify - all the vulnerabilities were found manually by a very real human, Yarden Porat.

The writeup was mostly human-written as well, just aimed at a broader audience - which explains the verbosity. We did work with a content writer to help shape the structure and flow, and I totally get that some parts read a bit “sheeny.” Feedback noted and appreciated - and yep, there’s more coming :)

btw likely missed with the direct link - we also found pre-auth RCE in CyberArk Conjur - cyata.ai/vault-fault

shahartal··on WhatsApp sues NSO Group for allegedly helping spies hack phones around the world
all fighter jet principals and employees should have arrest warrants out for them. those damn fighter jets makers, killing people around the world with their jets. I mean, what did they think they are making a fighter jet for, they chose to work there and should have known the risks of being in the jet fighter business.
shahartal··on Misfortune Cookie
fixed. anyone else experiencing trouble?
shahartal··on TR-069 allows many home routers supplied by ISPs to be compromised en masse
Original defcon presentation at http://shahart.al/I-hunt-TR-069-admins-shahar-tal-dc22.pdf
shahartal··on Hey developers, stop forcing me to login to unsubscribe
A relevant post: http://shahart.al/2013/07/13/on-the-perils-of-owning-a-vanit... (Also - check out the reddit thread [link in text])