Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site
MediumPublished Feb 13, 2026
## Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The error_description query parameter was directly interpolated into an HTML script tag without proper escaping, allowing attackers to execute arbitrary JavaScript in the context of the victim's session. ### Root cause The OAuth callback handler in `site/ai-playground/src/server.ts` directly interpolated the `authError` value, sourced from the `error_description` query parameter, into an inline `<script>` tag. ### Impact An attacker could craft a malicious link that, when clicked by a victim, would: - Steal user chat message history - Access all LLM interactions stored in the user's session. - Access connected MCP Servers - Interact with any MCP servers connected to the victim's session (public or authenticated/private), potentially allowing the attacker to perform actions on the victim's behalf ### Mitigation: - PR: https://github.com/cloudflare/agents/pull/841 - Agents-sdk users should upgrade to `agents@0.3.10` - Developers using `configureOAuthCallback` with custom error handling in their own applications should ensure all user-controlled input i...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| agents npm | < 0.3.10 | 0.3.10 |
Details and references
## Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The error_description query parameter was directly interpolated into an HTML script tag without proper escaping, allowing attackers to execute arbitrary JavaScript in the context of the victim's session. ### Root cause The OAuth callback handler in `site/ai-playground/src/server.ts` directly interpolated the `authError` value, sourced from the `error_description` query parameter, into an inline `<script>` tag. ### Impact An attacker could craft a malicious link that, when clicked by a victim, would: - Steal user chat message history - Access all LLM interactions stored in the user's session. - Access connected MCP Servers - Interact with any MCP servers connected to the victim's session (public or authenticated/private), potentially allowing the attacker to perform actions on the victim's behalf ### Mitigation: - PR: https://github.com/cloudflare/agents/pull/841 - Agents-sdk users should upgrade to `agents@0.3.10` - Developers using `configureOAuthCallback` with custom error handling in their own applications should ensure all user-controlled input is escaped before interpolation. ### Credits Disclosed responsibly by Nishant Kumawat
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
More agents advisories
All agents| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 13 | agents: cross-site scripting | Medium | 0.3.10 |
| Feb 3 | Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing | Medium | 0.3.7 |