PT-2026-51224 · Crawl4Ai · Crawl4Ai
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Crawl4AI versions prior to 0.8.7
Description
The Docker API server contains an authentication bypass issue caused by a hardcoded default JWT (JSON Web Token) signing key. A JWT is a compact, URL-safe means of representing claims to be transferred between two parties. Because the secret used to sign these tokens is publicly known, a remote attacker can forge valid tokens for any user to bypass authentication and gain full access to protected functionality.
Recommendations
Update to version 0.8.7.
Exploit
Fix
Code Injection
SSRF
XSS
Missing Authentication
Path traversal
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crawl4Ai