Skip to content

Known CVE

Crawl4AI < 0.8.0 - Local File Inclusion

The Crawl4AI Docker API endpoints accepted arbitrary URL schemes without an allow-list. An unauthenticated request with a file:// URL could read local files. Fixed in 0.8.0, which restricts accepted URL schemes.

CVE-2026-26217

Critical2026

cve2026 · crawl4ai · lfi · file-read

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website