Skip to content

Known CVE

Crawl4AI < 0.8.7 - Hardcoded JWT Signing Key Authentication Bypass

Crawl4AI Docker API server versions before 0.8.7 ship with a hardcoded default JWT signing key ("mysecret") used to sign and verify HS256 authentication tokens. Because the key is identical across every deployment where SECRET_KEY has not been overridden, an unauthenticated attacker can forge a valid Bearer token and use it to access every JWT-protected API endpoint (/md, /html, /screenshot, /pdf, /execute_js, /crawl, /ask).

CVE-2026-56265

Critical2026CVSS 9.8CWE-798

cve2026 · crawl4ai · auth-bypass · jwt · hardcoded-credentials · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website