CVE-2026-26217
Crawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th
Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote attackers to read arbitrary files from the server filesystem. An attacker can access sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and environment variables via /proc/self/environ, potentially exposing credentials, API keys, and internal application structure.
| CWE | CWE-22 |
| Vendor | unclecode |
| Product | crawl4ai |
| Published | Feb 12, 2026 |
| Last Updated | Jun 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unclecode crawl4ai
Be the first to know when new high vulnerabilities affecting unclecode crawl4ai are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
unclecode / Crawl4AI
0 < 0.8.0
References
Credits
Neo by ProjectDiscovery (https://neo.projectdiscovery.io)