Executive brief
Crawl4AI is a tool used to crawl and extract data from websites using a browser. A security flaw in its Docker API allows an attacker to send malicious commands that the system will execute without requiring a password. This could allow an attacker to take full control of the server, steal sensitive data, or access internal network resources.
Technical details
The Crawl4AI Docker API server improperly handles the 'browser_config.extra_args' parameter, allowing it to flow directly into Chromium launch arguments. An unauthenticated attacker can inject specific Chromium switches (such as --utility-cmd-prefix or --renderer-cmd-prefix) combined with --no-zygote to force Chromium to execute arbitrary commands as the container's runtime user. This bypasses a previous incomplete denylist-based fix from version 0.8.9. The vulnerability is reachable via the /crawl, /crawl/stream, and /crawl/job endpoints. Version 0.9.0 fixes this by establishing a trust boundary that forbids 'extra_args' in untrusted request bodies.
Affected products
- unclecode crawl4ai <= 0.8.9
Timeline
- 2026-06-18: advisory: GitHub Advisory GHSA-r253-r9jw-qg44 published
- 2026-06-18: patched: Version 0.9.0 released to address the vulnerability