<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 12:00:37 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-56266 — Crawl4AI - Server-Side Request Forgery via Direct Crawl Endpoints</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-56266</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Crawl4AI&lt;/p&gt;
&lt;p&gt;Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services and cloud metadata endpoints.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Crawl4AI&lt;/p&gt;
&lt;p&gt;Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services and cloud metadata endpoints.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-56266</guid>
    </item>
    <item>
      <title>GHSA-365w-hqf6-vxfg — Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-365w-hqf6-vxfg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: crawl4ai&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities in the Crawl4AI Docker API server affecting endpoints for crawling, markdown/LLM extraction, screenshots, PDFs, webhooks, monitoring, JavaScript execution, and configuration.&lt;/p&gt;
&lt;p&gt;### Vulnerabilities&lt;/p&gt;
&lt;p&gt;#### 1. Arbitrary File Write via /screenshot and /pdf (CWE-22, CVSS 9.1)&lt;/p&gt;
&lt;p&gt;The `output_path` parameter accepts arbitrary filesystem paths with no validation. An attacker can overwrite server files (DoS) or write to any appuser-writable location.&lt;/p&gt;
&lt;p&gt;**Fix:** Added `validate_output_path()` restricting writes to `CRAWL4AI_OUTPUT_DIR` (/tmp/crawl4ai-outputs by default). Added Pydantic `field_validator` rejecting `..` traversal sequences.&lt;/p&gt;
&lt;p&gt;#### 2. SSRF via Webhook URL (CWE-918, CVSS 8.6)&lt;/p&gt;
&lt;p&gt;Webhook URLs in `/crawl/job` and `/llm/job` accept internal/private IPs with no validation, enabling Server-Side Request Forgery against cloud metadata endpoints (169.254.169.254), internal services, and Docker networks.&lt;/p&gt;
&lt;p&gt;**Fix:** Added `validate_webhook_url()` with blocklist for RFC 1918, loopback, link-local, cloud metadata IPs and hostnames. Validation at both job submission and send time. Explicit `follow_redirects=False`.&lt;/p&gt;
&lt;p&gt;#### 3. Authentication Bypass on Monitor Endpoints (CWE-306, CVSS 6.5)&lt;/p&gt;
&lt;p&gt;The monitor router was mounted without `token_dep` dependency, making all monitoring endpoints (including destructive ones like `/monitor/actions/cleanup`) accessible without authentication.&lt;/p&gt;
&lt;p&gt;**Fix:** Added `dependencies=[Depends(token_dep)]` to monitor router. Add…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: crawl4ai&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities in the Crawl4AI Docker API server affecting endpoints for crawling, markdown/LLM extraction, screenshots, PDFs, webhooks, monitoring, JavaScript execution, and configuration.&lt;/p&gt;
&lt;p&gt;### Vulnerabilities&lt;/p&gt;
&lt;p&gt;#### 1. Arbitrary File Write via /screenshot and /pdf (CWE-22, CVSS 9.1)&lt;/p&gt;
&lt;p&gt;The `output_path` parameter accepts arbitrary filesystem paths with no validation. An attacker can overwrite server files (DoS) or write to any appuser-writable location.&lt;/p&gt;
&lt;p&gt;**Fix:** Added `validate_output_path()` restricting writes to `CRAWL4AI_OUTPUT_DIR` (/tmp/crawl4ai-outputs by default). Added Pydantic `field_validator` rejecting `..` traversal sequences.&lt;/p&gt;
&lt;p&gt;#### 2. SSRF via Webhook URL (CWE-918, CVSS 8.6)&lt;/p&gt;
&lt;p&gt;Webhook URLs in `/crawl/job` and `/llm/job` accept internal/private IPs with no validation, enabling Server-Side Request Forgery against cloud metadata endpoints (169.254.169.254), internal services, and Docker networks.&lt;/p&gt;
&lt;p&gt;**Fix:** Added `validate_webhook_url()` with blocklist for RFC 1918, loopback, link-local, cloud metadata IPs and hostnames. Validation at both job submission and send time. Explicit `follow_redirects=False`.&lt;/p&gt;
&lt;p&gt;#### 3. Authentication Bypass on Monitor Endpoints (CWE-306, CVSS 6.5)&lt;/p&gt;
&lt;p&gt;The monitor router was mounted without `token_dep` dependency, making all monitoring endpoints (including destructive ones like `/monitor/actions/cleanup`) accessible without authentication.&lt;/p&gt;
&lt;p&gt;**Fix:** Added `dependencies=[Depends(token_dep)]` to monitor router. Add…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-365w-hqf6-vxfg</guid>
    </item>
  </channel>
</rss>
