« Volver al listado

Kidocode

Kidocode Crawl4ai: vulnerabilidades y CVE

Kidocode Crawl4ai tiene 24 vulnerabilidades publicadas, 23 de ellas en los últimos 12 meses. 11 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE24
Últimos 12 meses23
Críticas11
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-91944Media (5.1)0.26%—15 sept 2026
crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as…
CVE-2026-91943Alta (8.3)0.35%—15 sept 2026
Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers…
CVE-2026-91942Media (5.1)0.24%—15 sept 2026
crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler…
CVE-2026-91940Alta (8.7)0.46%—15 sept 2026
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit…
CVE-2026-91941Alta (8.7)0.49%—15 sept 2026
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in…
CVE-2026-56260Alta (8.8)0.65%—12 jul 2026
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing…
CVE-2026-56259Alta (8.8)0.43%—12 jul 2026
Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables.…
CVE-2026-61429Alta (8.4)0.35%—11 jul 2026
PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects.…
CVE-2026-56261Crítica (9.2)0.51%—10 jul 2026
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can…
CVE-2026-57573Alta (8.6)0.45%—6 jul 2026
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path.…
CVE-2026-57572Crítica (10)0.94%—6 jul 2026
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker…
CVE-2026-57571Crítica (9.6)0.81%—6 jul 2026
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads…
CVE-2026-56264Crítica (9.2)0.49%—30 jun 2026
Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied JavaScript in the server's browser…
CVE-2026-56262Media (6.9)0.76%—24 jun 2026
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the…
CVE-2026-53755Alta (7.5)1.6%—23 jun 2026
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not to the proxy address. An unauthenticated request…
CVE-2026-53754Alta (7.5)0.43%—23 jun 2026
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination in deploy/docker/utils.py) used an explicit…
CVE-2026-53753Crítica (10)2.9%—23 jun 2026
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with…
CVE-2026-56263Media (5.3)0.34%—23 jun 2026
Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs and error messages via innerHTML without escaping. An attacker can submit a crafted crawl…
CVE-2026-56258Crítica (9.2)0.91%—23 jun 2026
Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to write files outside the intended directory via symlink and…
CVE-2026-56266Crítica (9.2)0.48%—22 jun 2026
Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can…
CVE-2026-56265Crítica (9.3)2.6%—21 jun 2026
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any…
CVE-2026-26217Crítica (9.2)2.0%—12 feb 2026
Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote…
CVE-2026-26216Crítica (10)1.7%—12 feb 2026
Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The…
CVE-2025-28197Crítica (9.1)0.36%—18 abr 2025
Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application14
  2. T1059 Command and Scripting Interpreter3
  3. T1090 Proxy3
  4. T1005 Data from Local System2
  5. T1210 Exploitation of Remote Services2
  6. T1078.001 Default Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.