GHSA-365w-hqf6-vxfg: Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
(updated )
Multiple security vulnerabilities in the Crawl4AI Docker API server affecting endpoints for crawling, markdown/LLM extraction, screenshots, PDFs, webhooks, monitoring, JavaScript execution, and configuration.
References
- github.com/advisories/GHSA-365w-hqf6-vxfg
- github.com/advisories/GHSA-53rg-46cm-4g2v
- github.com/advisories/GHSA-8qrg-7j2f-rf2h
- github.com/advisories/GHSA-g2pv-76hm-j4x9
- github.com/advisories/GHSA-xrfj-6m49-wfmm
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-229.yaml
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-230.yaml
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-239.yaml
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-3443.yaml
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-3449.yaml
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-596.yaml
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-798.yaml
- github.com/unclecode/crawl4ai
- github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfg
- nvd.nist.gov/vuln/detail/CVE-2026-56266
- www.vulncheck.com/advisories/crawl4ai-arbitrary-file-write-via-output-path-parameter
- www.vulncheck.com/advisories/crawl4ai-arbitrary-javascript-execution-via-execute-js-endpoint
- www.vulncheck.com/advisories/crawl4ai-authentication-bypass-via-hardcoded-jwt-signing-key
- www.vulncheck.com/advisories/crawl4ai-server-side-request-forgery-via-direct-crawl-endpoints
- www.vulncheck.com/advisories/crawl4ai-server-side-request-forgery-via-webhook-urls
- www.vulncheck.com/advisories/crawl4ai-stored-cross-site-scripting-in-monitor-dashboard
- www.vulncheck.com/advisories/crawl4ai-unauthenticated-access-to-monitor-endpoints-via-docker-api-server
Code Behaviors & Features
Detect and mitigate GHSA-365w-hqf6-vxfg with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →