PT-2026-51505 · Crawl4Ai · Crawl4Ai

CVE-2026-56258

·

Published

2026-06-16

·

Updated

2026-06-25

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Crawl4AI versions prior to 0.8.8
Description An arbitrary file write issue exists in the screenshot and PDF endpoints. Unauthenticated remote attackers can write files outside the intended directory by exploiting insufficient path validation and symlink following via the output path parameter. This is achieved through symlink and time-of-check-time-of-use (TOCTOU) attacks—a race condition where a system checks a condition (such as a file path) and then uses the result, but the condition changes between the check and the use. This can lead to potential code execution if the runtime user has write access to executable or cron locations.
Recommendations Update to version 0.8.8 or later. Avoid using the output path parameter in the screenshot and PDF endpoints until the update is applied.

Exploit

Fix

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56258
GHSA-7CX2-G3H9-382P
PYSEC-2026-228

Affected Products

Crawl4Ai