Crawl4ai
Vendor:
First CVE: Apr 18, 2025 · Active for 1 year
18
Total CVEs
More Total CVEs than 94% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Crawl4ai over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2025
15 months ago
Most Recent CVE
Jul 12, 2026
16 days ago
CVE Severity & Scoring
Crawl4ai18 CVEs
11%
50%
39%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (88.9%)
High2 (11.1%)
Unknown0 (0.0%)
User Interaction
None16 (88.9%)
Unknown0 (0.0%)
Required2 (11.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None18 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57572CRITICAL Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromi | Jul 6, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-56260CRITICAL Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesyst | Jul 12, 2026 | 9.1 | 41 | NO | NO |
CVE-2026-57571CRITICAL Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenc | Jul 6, 2026 | 9.6 | 41 | NO | NO |
CVE-2026-53753CRITICAL Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only b | Jun 23, 2026 | 10.0 | 41 | NO | NO |
CVE-2026-56259HIGH Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and | Jul 12, 2026 | 8.2 | 39 | NO | NO |
CVE-2026-57573HIGH Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not o | Jul 6, 2026 | 8.6 | 37 | NO | NO |
CVE-2026-56265CRITICAL Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can fo | Jun 21, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-56261HIGH Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without de | Jul 10, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-56264HIGH Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied J | Jun 30, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-26216CRITICAL Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code th | Feb 12, 2026 | 10.0 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Crawl4ai
Top CWEs
Versions
No cataloged versions.