PT-2026-57551 · Crawl4Ai · Crawl4Ai

CVE-2026-56260

·

Published

2026-06-16

·

Updated

2026-07-13

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Crawl4AI versions prior to 0.8.7
Description An arbitrary file write issue exists in the Docker API server. The '/screenshot' and '/pdf' endpoints do not validate the output path parameter, allowing the use of absolute paths or path-traversal values. This enables an attacker to write files to any location accessible by the application user, which can lead to the overwriting of server files, denial of service, or potential remote code execution.
Recommendations Update to version 0.8.7.

Exploit

Fix

DoS

RCE

XSS

Using Hardcoded Credentials

Path traversal

Missing Authentication

Code Injection

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-56260
GHSA-365W-HQF6-VXFG
GHSA-53RG-46CM-4G2V
GHSA-8QRG-7J2F-RF2H
GHSA-F23G-2F38-GG94
GHSA-G2PV-76HM-J4X9
GHSA-R9HW-78Q5-478G
GHSA-XRFJ-6M49-WFMM
PYSEC-2026-229
PYSEC-2026-230
PYSEC-2026-239
PYSEC-2026-3443
PYSEC-2026-3449
PYSEC-2026-596
PYSEC-2026-798

Affected Products

Crawl4Ai