CVE-2023-7080 is a high-severity vulnerability affecting Cloudflare Wrangler, specifically versions prior to 3.19.0 and 2.20.2. It allowed attackers on the local network to achieve arbitrary code execution within the Workers sandbox due to the V8 inspector listening on all network interfaces and lacking Origin/Host header validation. This could lead to compromise of local systems or, if --remote was used, production resources. The vulnerability has a CVSS score of 8.0 (HIGH), indicating a network-adjacent attack vector with low attack complexity, requiring user interaction (e.g., tricking a user into visiting a malicious website). The potential impact includes high confidentiality, integrity, and availability compromise. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for the vast majority of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2.20.2CPE match | cpe:2.3:a:cloudflare:wrangler:*:*:*:*:*:node.js:*:* | ||
>= 0, <= 2.0.0CPE match | cpe:2.3:a:cloudflare:wrangler:*:*:*:*:*:node.js:*:* | ||
>= 0, < 3.19.0CPE match | cpe:2.3:a:cloudflare:wrangler:*:*:*:*:*:node.js:*:* | ||
>= 0, <= 3.0.0CPE match | cpe:2.3:a:cloudflare:wrangler:*:*:*:*:*:node.js:*:* | ||
>= 2.0.0, < 2.20.2CPE matchmatch criteria | cpe:2.3:a:cloudflare:wrangler:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.