PT-2026-51506 · Crawl4Ai · Crawl4Ai

·

CVE-2026-56263

·

Published

2026-06-16

·

Updated

2026-07-12

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Crawl4AI versions prior to 0.8.7
Description A stored cross-site scripting issue exists in the monitor dashboard. The application renders crawl URLs and error messages using innerHTML without proper escaping. This allows an attacker to submit a crafted crawl request containing malicious markup, which then executes in the browser of an operator viewing the dashboard.
Recommendations Update to version 0.8.7 or later.

Exploit

Fix

SSRF

Missing Authentication

Path traversal

Using Hardcoded Credentials

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-56263
GHSA-365W-HQF6-VXFG
GHSA-53RG-46CM-4G2V
GHSA-8QRG-7J2F-RF2H
GHSA-F23G-2F38-GG94
GHSA-G2PV-76HM-J4X9
GHSA-R9HW-78Q5-478G
GHSA-XRFJ-6M49-WFMM
PYSEC-2026-229
PYSEC-2026-230
PYSEC-2026-239
PYSEC-2026-3443
PYSEC-2026-3449
PYSEC-2026-596
PYSEC-2026-798

Affected Products

Crawl4Ai