Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-7080

22
FAUCET Score

CVE-2023-7080 is a high-severity vulnerability affecting Cloudflare Wrangler, specifically versions prior to 3.19.0 and 2.20.2. It allowed attackers on the local network to achieve arbitrary code execution within the Workers sandbox due to the V8 inspector listening on all network interfaces and lacking Origin/Host header validation. This could lead to compromise of local systems or, if --remote was used, production resources. The vulnerability has a CVSS score of 8.0 (HIGH), indicating a network-adjacent attack vector with low attack complexity, requiring user interaction (e.g., tricking a user into visiting a malicious website). The potential impact includes high confidentiality, integrity, and availability compromise. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for the vast majority of vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2.20.2CPE match
cpe:2.3:a:cloudflare:wrangler:*:*:*:*:*:node.js:*:*
>= 0, <= 2.0.0CPE match
cpe:2.3:a:cloudflare:wrangler:*:*:*:*:*:node.js:*:*
>= 0, < 3.19.0CPE match
cpe:2.3:a:cloudflare:wrangler:*:*:*:*:*:node.js:*:*
>= 0, <= 3.0.0CPE match
cpe:2.3:a:cloudflare:wrangler:*:*:*:*:*:node.js:*:*
>= 2.0.0, < 2.20.2CPE matchmatch criteria
cpe:2.3:a:cloudflare:wrangler:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

8.5HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.1
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.58%
Probability of exploitation in next 30 days
EPSS Percentile
44.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0058 is in the 50th percentile among its peer group of 122 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: wranglerFixed in: 3.19.0
npmpatch availablevia ghsa
Product: wranglerFixed in: 2.20.2

Vendor Advisories (1)

npmGHSA-f8mp-x433-5wpfcritical

Arbitrary remote code execution within `wrangler dev` Workers sandbox

Jan 3, 2024

References

github.com / cloudflare/workers-sdk/issues/4430
Issue TrackingPatch
github.com / cloudflare/workers-sdk/pull/4437
Patch
github.com / cloudflare/workers-sdk/pull/4535
Patch
github.com / cloudflare/workers-sdk/pull/4550
Patch
github.com / cloudflare/workers-sdk/security/advisories/GHSA-f8mp-x433-5wpf
MitigationPatchThird Party Advisory