<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T19:10:36.017781+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-56258</id>
    <title>CVE-2026-56258 — Crawl4AI - Arbitrary File Write via output_path Symlink and TOCTOU</title>
    <updated>2026-10-05T19:10:36.019348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Crawl4AI</p>
<p>Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to write files outside the intended directory via symlink and time-of-check-time-of-use (TOCTOU) attacks on the output_path parameter. Remote attackers can exploit insufficient path validation and symlink following to achieve arbitrary file write and potential code execution on systems where the runtime user has write access to executable or cron locations.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-56258"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7cx2-g3h9-382p</id>
    <title>GHSA-7cx2-g3h9-382p — Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server</title>
    <updated>2026-10-05T19:10:36.019403+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: crawl4ai</p>
<p>### Summary</p>
<p>Three backward-compatible hardening fixes in the Docker API server. The headline issue is an arbitrary file write via the screenshot/PDF `output_path`.</p>
<p>### 1. Arbitrary file write via output_path symlink / TOCTOU (primary)</p>
<p>`POST /screenshot` and `POST /pdf` accept an `output_path` constrained to `ALLOWED_OUTPUT_DIR` by `validate_output_path`. The 0.8.7 check was string-only: it did not resolve symlinks, so a symlinked path component inside the output directory could redirect the write outside the directory, and the final `open()` followed symlinks. On a deployment where the runtime user can write executable/cron locations this is an arbitrary-write to code-execution primitive. The API is unauthenticated by default.</p>
<p>Fix: `validate_output_path` now resolves the real path (symlinks) of the parent and re-checks containment, and the write uses `O_NOFOLLOW` (`write_output_file`). `output_path` remains supported.</p>
<p>### 2. CRLF log injection (CWE-117)</p>
<p>User-controlled URLs/errors reflected into log lines could embed CR/LF and forge additional log entries. Fix: a logging filter strips CR/LF/control characters from all records.</p>
<p>### 3. Webhook request-header injection (CWE-93/CWE-113)</p>
<p>User-supplied webhook headers were sent verbatim, allowing CRLF and hop-by-hop / sensitive header injection on the outbound webhook request. Fix: webhook headers are validated (name pattern, no control characters, deny `Host`/`Content-Length`/`Transfer-Encoding`/`Authorization`/`Cookie`/.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7cx2-g3h9-382p"/>
  </entry>
</feed>
