PT-2026-57168 · Crawl4Ai · Crawl4Ai

CVE-2026-56261

·

Published

2026-06-16

·

Updated

2026-07-13

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Crawl4AI versions prior to 0.8.7
Description The Docker API server contains a server-side request forgery (SSRF) issue where the server makes requests to internal services due to a lack of destination validation for webhook URLs. This can lead to the exposure of cloud metadata credentials and access to internal APIs. The issue occurs at the '/crawl/job' and '/llm/job' endpoints when processing webhook URLs.
Recommendations Update to version 0.8.7.

Exploit

Fix

Code Injection

SSRF

XSS

Missing Authentication

Path traversal

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-56261
GHSA-365W-HQF6-VXFG
GHSA-53RG-46CM-4G2V
GHSA-8QRG-7J2F-RF2H
GHSA-F23G-2F38-GG94
GHSA-G2PV-76HM-J4X9
GHSA-R9HW-78Q5-478G
GHSA-XRFJ-6M49-WFMM
PYSEC-2026-229
PYSEC-2026-230
PYSEC-2026-239
PYSEC-2026-3443
PYSEC-2026-3449
PYSEC-2026-596
PYSEC-2026-798

Affected Products

Crawl4Ai