LOW
apify
CVE published 2026-06-10
CVE-2026-46497
Crawlee, a web scraping and browser automation library, is vulnerable to SSRF via sitemap-derived URLs from version 1.0.0 to before version 1.7.0. This issue is patched in version 1.7.0.