Executive brief
Crawl4AI, a tool used for web crawling and data extraction, contains a security flaw in its Docker API deployment. This vulnerability allows an unauthorized person to remotely read sensitive files from the server's filesystem, such as system passwords, configuration files, and internal credentials. This could lead to a full compromise of the server or the exposure of private API keys and application data.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the Docker API of Crawl4AI due to improper validation of URL schemes. The /execute_js, /screenshot, /pdf, and /html endpoints accept the 'file://' protocol, which allows an unauthenticated remote attacker to request local system files instead of remote web pages. By submitting a crafted POST request, an attacker can retrieve sensitive files such as /etc/passwd, /etc/shadow, or environment variables via /proc/self/environ. This vulnerability is classified as CWE-22 (Path Traversal) and has been addressed in version 0.8.0.
Affected products
- unclecode Crawl4AI < 0.8.0
Timeline
- 2026-01-16: advisory: Vendor published security advisory GHSA-vx9w-5cx4-9796
- 2026-02-12: disclosed: CVE-2026-26217 published to NVD
- 2026-02-12: patched: Version 0.8.0 released to address the vulnerability