Security: unclecode/crawl4ai
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Arbitrary file write via unconfined PDFContentScrapingStrategy fields in untrusted config bodiesGHSA-xpp7-j28w-2gvx published
Aug 31, 2026 by unclecodeHigh -
Denial of Service in PDFContentScrapingStrategy: unbounded remote PDF size and page countGHSA-v2rm-hvrj-2x9q published
Aug 31, 2026 by unclecodeModerate -
XSS in Docker Playground: crawl results rendered via innerHTML; PDF pipeline emits unescaped HTMLGHSA-7g3g-vhm6-79f3 published
Aug 31, 2026 by unclecodeModerate -
SSRF in PDFContentScrapingStrategy: PDF download follows redirects and bypasses egress SSRF controlsGHSA-q5rj-45vw-vp2g published
Aug 31, 2026 by unclecodeHigh -
DOM-based XSS in Docker Playground UI leads to operator API-token theftGHSA-m446-hp3q-qfxp published
Aug 31, 2026 by unclecodeHigh -
Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)GHSA-wm69-2pc3-rmmf published
Jun 18, 2026 by unclecodeHigh -
Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_argsGHSA-r253-r9jw-qg44 published
Jun 18, 2026 by unclecodeCritical -
Arbitrary file write (path traversal) in crawler downloads can lead to RCEGHSA-2jq4-q6vv-4cp3 published
Jun 18, 2026 by unclecodeCritical -
SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF checkGHSA-6qhc-x826-342c published
Jun 4, 2026 by unclecodeHigh -
Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker serverGHSA-7cx2-g3h9-382p published
Jun 4, 2026 by unclecodeHigh