PT-2026-53411 · Pypi · Crawl4Ai
Published
2026-06-29
·
Updated
2026-06-29
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Summary
The
safe eval expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi frame, f back, f builtins) do NOT start with underscore, enabling a complete sandbox escape to achieve arbitrary code execution.The attack requires no authentication (JWT disabled by default) and is triggered via
POST /crawl with a crafted extraction schema.Attack Vector
An attacker sends a
POST /crawl request with a JsonCssExtractionStrategy schema containing a malicious computed field expression that:- Creates a generator to access
gi frame - Walks the frame chain via
f back - Reaches
f builtinscontaining the realimport - Imports
osand executes arbitrary commands
Impact
Unauthenticated remote code execution inside the Docker container. An attacker can execute arbitrary system commands, read/write files, and exfiltrate secrets.
Fix Details
- Removed
eval()from computed field expression path entirely -- expressions now log a warning and return default value - Deleted
safe eval expression()function andSAFE EVAL BUILTINS(dead security-sensitive code) functionkey with Python callables still works for SDK users- Replaced
eval()in/config/dumpwith JSON-based input validated by Pydantic - Fixed hook manager sandbox: stripped
builtins,loader,specfrom injected modules; removedgetattr,setattr,type,build classfrom allowed builtins
Workarounds
- Upgrade to the patched version (recommended)
- Enable JWT authentication via
CRAWL4AI API TOKENenvironment variable - Restrict network access to the Docker API
Credits
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crawl4Ai