PT-2026-57550 · Crawl4Ai · Crawl4Ai
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Crawl4AI versions prior to 0.8.8
Description
The Docker API server contains credential exfiltration flaws due to improper input validation and insecure configuration handling. Unauthenticated attackers can redirect LLM API calls to external endpoints and read arbitrary environment variables. This is achieved by exploiting the '/md', '/llm', and '/llm/job' endpoints by providing a malicious
base url parameter and setting the api token to env:VARIABLE NAME. This allows the exfiltration of provider API keys and server secrets, such as the JWT SECRET KEY, which can lead to authentication bypass and session forgery.Recommendations
Update to version 0.8.8.
Restrict access to the '/md', '/llm', and '/llm/job' endpoints to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
SSRF
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crawl4Ai