Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-56260: Crawl4AI - Malicious files can be written to server

CVE-2026-56260 CVE-2026-56260 PYSEC-2026-596
Summary

The Crawl4AI software before version 0.8.7 allows attackers to write malicious files to the server. This could cause the server to crash or become unusable. To fix this, update Crawl4AI to version 0.8.7 or later.

What to do
  • Update crawl4ai to version 0.8.7.
  • Update unclecode crawl4ai to version 0.8.7.
Affected software
Ecosystem VendorProductAffected versions
crawl4ai crawl4ai < 0.8.7
pip crawl4ai <= 0.8.6
Fix: upgrade to 0.8.7
PyPI unclecode crawl4ai < 0.8.7
Fix: upgrade to 0.8.7
kidocode crawl4ai < 0.8.7
cpe:2.3:a:kidocode:crawl4ai:*:*:*:*:*:*:*:*
PyPI crawl4ai < 0.8.7
Fix: upgrade to 0.8.7
Original title
Crawl4AI - Arbitrary File Write via output_path Parameter
Original description
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.
nvd CVSS3.1 9.1
nvd CVSS4.0 8.8
Vulnerability type
CWE-22 Path Traversal
CWE-79 Cross-site Scripting (XSS)
CWE-94 Code Injection
CWE-306 Missing Authentication for Critical Function
CWE-798 Use of Hard-coded Credentials
CWE-918 Server-Side Request Forgery (SSRF)
Published: 12 Jul 2026 · Updated: 16 Jul 2026 · First seen: 12 Jul 2026