Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Crawl4AI - LLM Credential Exfiltration via base_url and Environment Variable Resolution
Vulnerability Description
Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by supplying a malicious base_url parameter and setting api_token to env:VARIABLE_NAME to exfiltrate provider API keys and server secrets including JWT SECRET_KEY for authentication bypass.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
信息暴露
Vulnerability Title
UncleCode Crawl4AI 信息泄露漏洞
Vulnerability Description
UncleCode Crawl4AI是新加坡UncleCode个人开发者的一款AI驱动的爬虫软件。 UncleCode Crawl4AI 0.8.8之前版本存在信息泄露漏洞,该漏洞源于Docker API服务器中的凭据渗出漏洞,攻击者可以通过提供恶意base_url参数并将api_token设置为env:VARIABLE_NAME,利用未经验证的/md、/llm和/llm/job端点,将LLM API调用重定向到攻击者控制的端点并读取任意环境变量,从而渗出提供商API密钥和服务器密钥(包括用于身份验证绕过
CVSS Information
N/A
Vulnerability Type
N/A