Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-56260: Crawl4AI - Malicious files can be written to server
CVE-2026-56260
CVE-2026-56260
PYSEC-2026-596
Summary
The Crawl4AI software before version 0.8.7 allows attackers to write malicious files to the server. This could cause the server to crash or become unusable. To fix this, update Crawl4AI to version 0.8.7 or later.
What to do
- Update crawl4ai to version 0.8.7.
- Update unclecode crawl4ai to version 0.8.7.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | crawl4ai | crawl4ai | < 0.8.7 |
| pip | – | crawl4ai |
<= 0.8.6 Fix: upgrade to 0.8.7
|
| PyPI | unclecode | crawl4ai |
< 0.8.7 Fix: upgrade to 0.8.7
|
| – | kidocode | crawl4ai |
< 0.8.7 cpe:2.3:a:kidocode:crawl4ai:*:*:*:*:*:*:*:* |
| PyPI | – | crawl4ai |
< 0.8.7 Fix: upgrade to 0.8.7
|
Original title
Crawl4AI - Arbitrary File Write via output_path Parameter
Original description
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.
nvd CVSS3.1
9.1
nvd CVSS4.0
8.8
Vulnerability type
CWE-22
Path Traversal
CWE-79
Cross-site Scripting (XSS)
CWE-94
Code Injection
CWE-306
Missing Authentication for Critical Function
CWE-798
Use of Hard-coded Credentials
CWE-918
Server-Side Request Forgery (SSRF)
- https://github.com/unclecode/crawl4ai
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfg
- https://www.vulncheck.com/advisories/crawl4ai-arbitrary-file-write-via-output-pa...
- https://github.com/advisories/GHSA-365w-hqf6-vxfg
- https://nvd.nist.gov/vuln/detail/CVE-2026-56266
- https://www.vulncheck.com/advisories/crawl4ai-stored-cross-site-scripting-in-mon...
- https://www.vulncheck.com/advisories/crawl4ai-authentication-bypass-via-hardcode...
- https://www.vulncheck.com/advisories/crawl4ai-server-side-request-forgery-via-di... Vendor Advisory
- https://www.vulncheck.com/advisories/crawl4ai-unauthenticated-access-to-monitor-...
- https://www.vulncheck.com/advisories/crawl4ai-arbitrary-javascript-execution-via...
- https://github.com/advisories/GHSA-xrfj-6m49-wfmm Vendor Advisory
- https://github.com/advisories/GHSA-g2pv-76hm-j4x9 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56264... Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56263... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56263 Vendor Advisory
- https://github.com/advisories/GHSA-53rg-46cm-4g2v Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56264 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56265... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56265 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56261... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56261 Vendor Advisory
- https://www.vulncheck.com/advisories/crawl4ai-server-side-request-forgery-via-we...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56262... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56262 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56266... Vendor Advisory
- https://github.com/advisories/GHSA-8qrg-7j2f-rf2h Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56260... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56260 Vendor Advisory
Published: 12 Jul 2026 · Updated: 16 Jul 2026 · First seen: 12 Jul 2026