PT-2026-51506 · Crawl4Ai · Crawl4Ai
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Crawl4AI versions prior to 0.8.7
Description
A stored cross-site scripting issue exists in the monitor dashboard. The application renders crawl URLs and error messages using
innerHTML without proper escaping. This allows an attacker to submit a crafted crawl request containing malicious markup, which then executes in the browser of an operator viewing the dashboard.Recommendations
Update to version 0.8.7 or later.
Exploit
Fix
SSRF
Missing Authentication
Path traversal
Using Hardcoded Credentials
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crawl4Ai