CVE-2026-56260
Crawl4AI Crawl4AI, crawl4ai
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.
- CVSS
- 8.8
- EPSS
- 0.42% 34.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.12