Kidocode

Crawl4ai

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 12.07.2026 12:16:45
  • Zuletzt bearbeitet 14.07.2026 18:25:42

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute o...

  • EPSS 0.31%
  • Veröffentlicht 12.07.2026 12:16:45
  • Zuletzt bearbeitet 14.07.2026 18:29:21

Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauth...

  • EPSS 0.37%
  • Veröffentlicht 10.07.2026 13:57:52
  • Zuletzt bearbeitet 13.07.2026 15:21:04

Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to ...

  • EPSS 0.53%
  • Veröffentlicht 06.07.2026 20:16:21
  • Zuletzt bearbeitet 08.07.2026 20:16:53

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that...

  • EPSS 0.26%
  • Veröffentlicht 06.07.2026 20:11:15
  • Zuletzt bearbeitet 07.07.2026 19:07:47

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs str...

Exploit
  • EPSS 0.6%
  • Veröffentlicht 06.07.2026 20:09:52
  • Zuletzt bearbeitet 07.07.2026 19:07:22

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A ...

  • EPSS 0.33%
  • Veröffentlicht 30.06.2026 22:08:26
  • Zuletzt bearbeitet 06.07.2026 16:08:36

Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied JavaScript in the server's browser context with --disable-web-security ...

  • EPSS 0.42%
  • Veröffentlicht 24.06.2026 11:53:13
  • Zuletzt bearbeitet 26.06.2026 02:00:03

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipu...

  • EPSS 2.09%
  • Veröffentlicht 23.06.2026 18:17:18
  • Zuletzt bearbeitet 29.06.2026 16:57:39

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame ...

  • EPSS 0.27%
  • Veröffentlicht 23.06.2026 18:16:34
  • Zuletzt bearbeitet 29.06.2026 16:53:02

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination in deploy/docker/utils.py) used an explicit IPv4/IPv6 CIDR blocklist that missed s...