PT-2026-51224 · Crawl4Ai · Crawl4Ai

·

CVE-2026-56265

·

Published

2026-06-16

·

Updated

2026-07-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Crawl4AI versions prior to 0.8.7
Description The Docker API server contains an authentication bypass issue caused by a hardcoded default JWT (JSON Web Token) signing key. A JWT is a compact, URL-safe means of representing claims to be transferred between two parties. Because the secret used to sign these tokens is publicly known, a remote attacker can forge valid tokens for any user to bypass authentication and gain full access to protected functionality.
Recommendations Update to version 0.8.7.

Exploit

Fix

Code Injection

SSRF

XSS

Missing Authentication

Path traversal

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-56265
GHSA-365W-HQF6-VXFG
GHSA-53RG-46CM-4G2V
GHSA-8QRG-7J2F-RF2H
GHSA-F23G-2F38-GG94
GHSA-G2PV-76HM-J4X9
GHSA-R9HW-78Q5-478G
GHSA-XRFJ-6M49-WFMM
PYSEC-2026-229
PYSEC-2026-230
PYSEC-2026-239
PYSEC-2026-3443
PYSEC-2026-3449
PYSEC-2026-596
PYSEC-2026-798

Affected Products

Crawl4Ai