Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.
References
| Link | Resource |
|---|---|
| https://github.com/unclecode/crawl4ai | Product |
| https://github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfg | Vendor Advisory |
| https://www.vulncheck.com/advisories/crawl4ai-arbitrary-file-write-via-output-path-parameter | Third Party Advisory |
Configurations
History
14 Jul 2026, 18:25
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Kidocode
Kidocode crawl4ai |
|
| CPE | cpe:2.3:a:kidocode:crawl4ai:*:*:*:*:*:*:*:* | |
| References | () https://github.com/unclecode/crawl4ai - Product | |
| References | () https://github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfg - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/crawl4ai-arbitrary-file-write-via-output-path-parameter - Third Party Advisory |
12 Jul 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-12 12:16
Updated : 2026-07-14 18:25
NVD link : CVE-2026-56260
Mitre link : CVE-2026-56260
CVE.ORG link : CVE-2026-56260
JSON object : View
Products Affected
kidocode
- crawl4ai
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
