CVE-2026-56266
EUVD-2026-3836622.06.2026, 22:16
Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services and cloud metadata endpoints.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kidocode | crawl4ai | 𝑥 < 0.8.7 |
𝑥
= Vulnerable software versions