Jina Ai · Jina-Ai Reader · CVE-2026-18647
**Name of the Vulnerable Software and Affected Versions**
jina-ai reader versions up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1
**Description**
A flaw in the Crawler/Puppeteer component allows remote attackers to perform server-side request forgery (SSRF), a technique where an attacker induces a server-side application to make requests to an unintended location. The issue resides in the `isValidTLD()` function within the `/backend/functions/src/cloud-functions/crawler.ts` file.
**Recommendations**
As a temporary workaround, restrict the use of the `isValidTLD()` function in the `/backend/functions/src/cloud-functions/crawler.ts` file to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.