Junglewise Threat Intelligence

CVE-2026-56258: Crawl4AI arbitrary file write in screenshot and PDF endpoints

CVE-2026-56258 · Severity: high · CVSS 8.1 · Published 2026-06-23

Technologies: crawl4ai (PyPI). Vendors: PyPI.

Executive brief

Crawl4AI, a tool used for web crawling and data extraction, contains a security flaw in its screenshot and PDF generation features. An unauthenticated attacker can trick the system into writing files to unauthorized locations on the server, such as system configuration or executable folders. This could allow an attacker to take full control of the server or disrupt operations.

Technical details

Crawl4AI's Docker API server is vulnerable to an arbitrary file write via the 'output_path' parameter in the /screenshot and /pdf endpoints. The vulnerability stems from insufficient path validation in the 'validate_output_path' function, which performed string-only checks without resolving symlinks. By exploiting a time-of-check-time-of-use (TOCTOU) race condition or using symlinks within the allowed output directory, a remote, unauthenticated attacker can write files to restricted locations. If the runtime user has sufficient permissions, this can lead to remote code execution by overwriting binaries or cron jobs. Version 0.8.8 fixes this by resolving real paths during validation and using the O_NOFOLLOW flag during file writes.

Affected products

  • unclecode Crawl4AI < 0.8.8

Timeline

  • 2026-06-04: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: NVD publication date

References

Related threats