Skip to content

Known CVE

Crawl4AI <= 0.8.6 - Remote Code Execution

Crawl4AI through 0.8.6 ships a Docker API server that exposes an unauthenticated /crawl endpoint. The computed field type of JsonCssExtractionStrategy evaluates a user supplied expression inside an AST based sandbox that does not restrict attribute access on generator frame objects. A generator expression can therefore reach gi_frame.f_back, walk the caller chain to f_builtins, recover __import__ and execute arbitrary operating system commands as the user running the container.

CVE-2026-53753

Critical2026CVSS 10CWE-94

cve2026 · crawl4ai · unclecode · rce · sandbox-escape

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website