CVE-2026-56260 is an arbitrary file write vulnerability in Crawl4AI before 0.8.7. The vulnerability exists in the Docker API server's /screenshot and /pdf endpoints, where the output_path parameter accepts arbitrary filesystem paths without validation. This allows an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files a [truncated]
CVE-2026-56263 is a stored cross-site scripting vulnerability in the Crawl4AI monitor dashboard. The vulnerability renders crawl URLs and error messages via innerHTML without escaping. An attacker can submit a crafted crawl request with malicious markup that executes in an operator's browser when viewing the dashboard. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Crawl4AI versions [truncated]
CVE-2026-56258 is a critical vulnerability in Crawl4AI before version 0.8.8. The vulnerability allows unauthenticated attackers to write files outside the intended directory via symlink and time-of-check-time-of-use (TOCTOU) attacks on the output_path parameter. This can lead to potential code execution on systems where the runtime user has write access to executable or cron locations. The vulnerability h [truncated]
CVE-2026-56265 is a critical authentication bypass vulnerability in Crawl4AI before version 0.8.7. The vulnerability is caused by a hardcoded default JWT signing key in the Docker API server. This allows attackers who know the default key to forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality. The CVSS score for this vulnerability is [truncated]