Known Vulnerabilities for Crawl4ai by Unclecode
Listed below are 9 of the newest known vulnerabilities associated with "Crawl4ai" by "Unclecode".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56266 json | Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoi... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-56265 json | Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docke... | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56263 json | Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs a... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-56262 json | Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthentic... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-56258 json | Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthen... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-53755 json | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destina... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-53754 json | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (valid... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-53753 json | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the co... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-40160 json | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs di... | Not Provided | 2026-04-10 | 2026-04-13 |