<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:48:40.074340+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-53753</id>
    <title>CVE-2026-53753 — Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API</title>
    <updated>2026-10-03T10:48:40.075928+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> unclecode crawl4ai</p>
<p>Crawl4AI is an open-source LLM friendly web crawler &amp; scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f_back, f_builtins) do NOT start with underscore, enabling a complete sandbox escape to achieve arbitrary code execution. The attack requires no authentication (JWT disabled by default) and is triggered via POST /crawl with a crafted extraction schema. This vulnerability is fixed in 0.8.7.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-53753"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qxjp-w3pj-48m7</id>
    <title>GHSA-qxjp-w3pj-48m7 — Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API</title>
    <updated>2026-10-03T10:48:40.075988+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: crawl4ai</p>
<p>### Summary</p>
<p>The `_safe_eval_expression()` function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (`gi_frame`, `f_back`, `f_builtins`) do NOT start with underscore, enabling a complete sandbox escape to achieve arbitrary code execution.</p>
<p>The attack requires no authentication (JWT disabled by default) and is triggered via `POST /crawl` with a crafted extraction schema.</p>
<p>### Attack Vector</p>
<p>An attacker sends a `POST /crawl` request with a `JsonCssExtractionStrategy` schema containing a malicious computed field expression that:
1. Creates a generator to access `gi_frame`
2. Walks the frame chain via `f_back`
3. Reaches `f_builtins` containing the real `__import__`
4. Imports `os` and executes arbitrary commands</p>
<p>### Impact</p>
<p>Unauthenticated remote code execution inside the Docker container. An attacker can execute arbitrary system commands, read/write files, and exfiltrate secrets.</p>
<p>### Fix Details</p>
<p>1. Removed `eval()` from computed field expression path entirely -- expressions now log a warning and return default value
2. Deleted `_safe_eval_expression()` function and `_SAFE_EVAL_BUILTINS` (dead security-sensitive code)
3. `function` key with Python callables still works for SDK users
4. Replaced `eval()` in `/config/dump` with JSON-based input validated by Pydantic
5. Fixed hook_manager sandbox: stripped `__builtins__`, `__loader__`, `__spec__` from injected modules; remove…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qxjp-w3pj-48m7"/>
  </entry>
</feed>
