CVE-2026-56260
EUVD-2026-4322712.07.2026, 12:16
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kidocode | crawl4ai | 𝑥 < 0.8.7 |
𝑥
= Vulnerable software versions