Repository navigation
Security: unclecode/crawl4ai
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Untrusted-config gate bypass via dict-wrapper laundering leaks server env vars (LLM keys, SECRET_KEY)GHSA-5w5p-vcv6-mm3f published
Sep 23, 2026 by unclecodeHigh -
SSRF with response disclosure via link_preview_config: the URL seeder fetches links outside the egress controlsGHSA-wh5w-hmj3-vgg7 published
Sep 23, 2026 by unclecodeHigh -
Blind SSRF via robots.txt fetch in RobotsParser.can_fetch bypasses the Docker server egress controlsGHSA-f77g-77vp-r96v published
Sep 23, 2026 by unclecodeModerate -
Arbitrary file write via unconfined PDFContentScrapingStrategy fields in untrusted config bodiesGHSA-xpp7-j28w-2gvx published
Aug 31, 2026 by unclecodeHigh -
Denial of Service in PDFContentScrapingStrategy: unbounded remote PDF size and page countGHSA-v2rm-hvrj-2x9q published
Aug 31, 2026 by unclecodeModerate -
XSS in Docker Playground: crawl results rendered via innerHTML; PDF pipeline emits unescaped HTMLGHSA-7g3g-vhm6-79f3 published
Aug 31, 2026 by unclecodeModerate -
SSRF in PDFContentScrapingStrategy: PDF download follows redirects and bypasses egress SSRF controlsGHSA-q5rj-45vw-vp2g published
Aug 31, 2026 by unclecodeHigh -
DOM-based XSS in Docker Playground UI leads to operator API-token theftGHSA-m446-hp3q-qfxp published
Aug 31, 2026 by unclecodeHigh -
Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)GHSA-wm69-2pc3-rmmf published
Jun 18, 2026 by unclecodeHigh -
Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_argsGHSA-r253-r9jw-qg44 published
Jun 18, 2026 by unclecodeCritical