PT-2026-51505 · Crawl4Ai · Crawl4Ai
CVE-2026-56258
·
Published
2026-06-16
·
Updated
2026-06-25
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Crawl4AI versions prior to 0.8.8
Description
An arbitrary file write issue exists in the screenshot and PDF endpoints. Unauthenticated remote attackers can write files outside the intended directory by exploiting insufficient path validation and symlink following via the
output path parameter. This is achieved through symlink and time-of-check-time-of-use (TOCTOU) attacks—a race condition where a system checks a condition (such as a file path) and then uses the result, but the condition changes between the check and the use. This can lead to potential code execution if the runtime user has write access to executable or cron locations.Recommendations
Update to version 0.8.8 or later.
Avoid using the
output path parameter in the screenshot and PDF endpoints until the update is applied.Exploit
Fix
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crawl4Ai