Executive brief
ScrapeGraphAI, a Python library used for automated web scraping using large language models, contains a security flaw in its code generation component. An attacker could potentially execute unauthorized operating system commands on the server or machine running the library. This could lead to full system compromise, data theft, or disruption of automated scraping operations.
Technical details
An OS command injection vulnerability exists in ScrapeGraphAI (scrapegraph-ai) versions up to and including 1.74.0. The flaw is located within the 'create_sandbox_and_execute' function in 'scrapegraphai/nodes/generate_code_node.py'. The 'GenerateCodeNode' component fails to properly neutralize special elements, allowing an attacker to inject and execute arbitrary shell commands. While the attack vector is described as remote, it typically requires some form of user interaction or processing of untrusted input through the scraping pipeline. As of the advisory date, the vendor has not responded to disclosure attempts, and a public exploit (PoC) is available.
Affected products
- ScrapeGraphAI scrapegraph-ai up to 1.74.0
Timeline
- 2026-03-18: disclosed: Initial public disclosure via GitHub issue
- 2026-04-05: advisory: NVD publication date