CVE-2026-56266
Crawl4AI Crawl4AI, crawl4ai 취약점
Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services and cloud metadata endpoints.
- 대응 우선순위
- 점검
- CVSS
- 9.2
- EPSS
- 0.28% 백분위 19.7% · 2026.07.20 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.23