Kidocode maintains the Crawl4AI web-crawling tool, a focused product where observed vulnerabilities center on critical control-flow and data-handling weaknesses: code injection, path traversal, and server-side request forgery. These classes reflect the inherent risks of a tool that processes untrusted web content and constructs filesystem and network operations from external input. Current severity, exploitation, and disclosure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kidocode over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-53753CRITICAL Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only b | Jun 23, 2026 | 10.0 | 43 | NO | NO |
CVE-2026-57572CRITICAL Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromi | Jul 6, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-56260CRITICAL Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesyst | Jul 12, 2026 | 9.1 | 41 | NO | NO |
CVE-2026-57571CRITICAL Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenc | Jul 6, 2026 | 9.6 | 41 | NO | NO |
CVE-2026-56265CRITICAL Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can fo | Jun 21, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-56259HIGH Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and | Jul 12, 2026 | 8.2 | 39 | NO | NO |
CVE-2026-57573HIGH Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not o | Jul 6, 2026 | 8.6 | 37 | NO | NO |
CVE-2026-56258HIGH Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to write files outside the intended d | Jun 23, 2026 | 8.1 | 36 | NO | NO |
CVE-2026-56261HIGH Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without de | Jul 10, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-53755HIGH Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not to the pro | Jun 23, 2026 | 7.5 | 35 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kidocode.
Media articles that mention a CVE ID that affects a product developed by Kidocode — matched by CVE ID, not by vendor name.