Description
An Insecure Direct Object Reference (CWE-639) has been found to exist in createHeaderBasedEmailResolver() function within the Cloudflare Agents SDK.
Recommendation
Update the agents package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.3.7
- Patched version(s): 0.3.7
References
Could your website be exposed too?
SmartScanner can check your website for Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR) - CVE-2024-22206
- Qwik City has a CSRF Protection Bypass via Content-Type Header Validation - CVE-2026-25151
- Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4) - CVE-2026-41321
- Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial - CVE-2026-33940


