CVE-2017-7235: Cloudflare-Scrape Project Cloudflare-Scrape

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that executes arbitrary Python code against any cfscrape user who scrapes that website. This is fixed in 1.8.0.

Affected products

  • Cloudflare-Scrape Project Cloudflare-Scrape: version 1.6.6 only; version 1.6.7 only; version 1.6.8 only; version 1.7.0 only; version 1.7.1 only

Published 2017-03-23. Last modified 2026-06-17.