Junglewise Threat Intelligence

Crawl4AI unauthenticated RCE via Chromium launch-argument injection

Severity: critical · CVSS 10 · Published 2026-06-18

Technologies: crawl4ai (PyPI). Vendors: PyPI.

Executive brief

Crawl4AI is a tool used to crawl and extract data from websites using a browser. A security flaw in its Docker API allows an attacker to send malicious commands that the system will execute without requiring a password. This could allow an attacker to take full control of the server, steal sensitive data, or access internal network resources.

Technical details

The Crawl4AI Docker API server improperly handles the 'browser_config.extra_args' parameter, allowing it to flow directly into Chromium launch arguments. An unauthenticated attacker can inject specific Chromium switches (such as --utility-cmd-prefix or --renderer-cmd-prefix) combined with --no-zygote to force Chromium to execute arbitrary commands as the container's runtime user. This bypasses a previous incomplete denylist-based fix from version 0.8.9. The vulnerability is reachable via the /crawl, /crawl/stream, and /crawl/job endpoints. Version 0.9.0 fixes this by establishing a trust boundary that forbids 'extra_args' in untrusted request bodies.

Affected products

  • unclecode crawl4ai <= 0.8.9

Timeline

  • 2026-06-18: advisory: GitHub Advisory GHSA-r253-r9jw-qg44 published
  • 2026-06-18: patched: Version 0.9.0 released to address the vulnerability

References

Related threats