Technology · PyPI
crawl4ai (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 29 vulnerabilities in crawl4ai (PyPI): 0 in the last 7 days and 13 in the last 90 days, 9 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91944, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 13
- Critical, all time
- 9
- Exploited in the wild
- 0
About crawl4ai (PyPI)
An open-source Python library designed for crawling and scraping web content for use in large language models.
Latest crawl4ai (PyPI) vulnerabilities
- CVE-2026-91944: crawl4ai DOM-based XSS in Playground UImediumCVSS 6.1EPSS 0.3%
- CVE-2026-91943: Crawl4AI PDFContentScrapingStrategy server-side request forgeryhighCVSS 7.7EPSS 0.4%
- CVE-2026-91942: crawl4ai DOM-based XSS in Docker Playground via innerHTMLmediumCVSS 5.4EPSS 0.2%
- CVE-2026-91941: Crawl4AI uncontrolled resource consumption in PDFContentScrapingStrategyhighCVSS 7.5EPSS 0.5%
- CVE-2026-91940: crawl4ai arbitrary file write in PDFContentScrapingStrategyhighCVSS 7.5EPSS 0.5%
- CVE-2026-56260: Crawl4AI arbitrary file write in Docker API server screenshot and pdf endpointscriticalCVSS 9.1EPSS 0.7%
- CVE-2026-56259: Crawl4AI credential exfiltration in Docker API serverhighCVSS 8.2EPSS 0.4%
- CVE-2026-56261: Crawl4AI SSRF in Docker API webhook endpointshighCVSS 8.6
- CVE-2025-28197: PYSEC-2026-1281 - Crawl4AI SSRF vulnerabilitymediumCVSS 4EPSS 0.4%
- CVE-2026-57573: unclecode Crawl4AI SSRF in Docker API streaming pathhighCVSS 8.6EPSS 0.4%
- CVE-2026-57572: unclecode Crawl4AI remote code execution in Docker API servercriticalCVSS 10EPSS 0.9%
- CVE-2026-57571: UncleCode Crawl4AI Path Traversal in Crawler DownloadscriticalCVSS 9.6EPSS 0.8%
- CVE-2026-56264: Crawl4AI arbitrary JavaScript execution in Docker API serverhighCVSS 8.1
- CVE-2026-56262: Crawl4AI authentication bypass in monitor router endpointsmediumCVSS 6.5
- CVE-2026-53755: unclecode Crawl4AI SSRF via proxy settings in Docker API serverhighCVSS 8.6EPSS 1.6%
- CVE-2026-53754: unclecode Crawl4AI SSRF in Docker API serverhighCVSS 7.5EPSS 0.4%
- CVE-2026-53753: unclecode Crawl4AI sandbox escape in _safe_eval_expressioncriticalCVSS 9.8EPSS 2.9%
- CVE-2026-56263: Crawl4AI stored XSS in monitor dashboardmediumCVSS 6.1
- CVE-2026-56258: Crawl4AI arbitrary file write in screenshot and PDF endpointshighCVSS 8.1EPSS 0.9%
- CVE-2026-56266: unclecode Crawl4AI SSRF in crawl and extraction endpointshighCVSS 8.6
- CVE-2026-56265: Crawl4AI hardcoded JWT signing key in Docker API servercriticalCVSS 9.8EPSS 2.6%
- Crawl4AI SSRF in Docker server streaming crawl pathhighCVSS 8.6
- Crawl4AI unauthenticated RCE via Chromium launch-argument injectioncriticalCVSS 10
- Crawl4AI path traversal in crawler downloads leads to RCEcriticalCVSS 9.6
- Crawl4AI arbitrary file write and injection in Docker serverhighCVSS 8.1
Most severe crawl4ai (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-26216: unclecode Crawl4AI remote code execution in Docker API hookscriticalCVSS 10EPSS 1.7%
- CVE-2026-57572: unclecode Crawl4AI remote code execution in Docker API servercriticalCVSS 10EPSS 0.9%
- Crawl4AI unauthenticated RCE via Chromium launch-argument injectioncriticalCVSS 10
- CVE-2026-53753: unclecode Crawl4AI sandbox escape in _safe_eval_expressioncriticalCVSS 9.8EPSS 2.9%
- CVE-2026-56265: Crawl4AI hardcoded JWT signing key in Docker API servercriticalCVSS 9.8EPSS 2.6%
- unclecode Crawl4AI multiple vulnerabilities in Docker API servercriticalCVSS 9.8
- CVE-2026-57571: UncleCode Crawl4AI Path Traversal in Crawler DownloadscriticalCVSS 9.6EPSS 0.8%
- Crawl4AI path traversal in crawler downloads leads to RCEcriticalCVSS 9.6
- CVE-2026-56260: Crawl4AI arbitrary file write in Docker API server screenshot and pdf endpointscriticalCVSS 9.1EPSS 0.7%
- CVE-2026-26217: unclecode Crawl4AI local file inclusion in Docker APIhighCVSS 8.6EPSS 2.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 7 | 3 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 5 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/crawl4ai.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "crawl4ai (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/crawl4ai, 26 September 2026.