PT-2026-56004 · Crawl4Ai · Crawl4Ai

·

CVE-2026-57573

·

Published

2026-06-18

·

Updated

2026-07-08

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Crawl4AI versions prior to 0.9.0
Description The Docker API server fails to apply Server-Side Request Forgery (SSRF) destination checks on the streaming path. A remote unauthenticated client can exploit this by calling the 'POST /crawl/stream' endpoint or the 'POST /crawl' endpoint with the crawler config.stream variable set to true. The handle stream crawl request() function passes seed URLs directly to the crawler without validation, allowing the server to fetch and stream response bodies from internal, private, or link-local addresses.
Recommendations Update to version 0.9.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57573
GHSA-WM69-2PC3-RMMF
PYSEC-2026-2140

Affected Products

Crawl4Ai