crawl4ai 在 0.9.3 版本之前,其 Docker Playground 界面中存在基于 DOM 的跨站脚本(XSS)漏洞。该漏洞源于将不可信的爬取结果直接赋值给 。攻击者可以通过构造包含事件处理器标记的恶意 PDF,在 Playground 源中执行 JavaScript 代码,从而窃取 中的 API 令牌,进而实现经过身份验证的 API 滥用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91943 | 7.7 HIGH | Crawl4AI before 0.9.3 SSRF via PDFContentScrapingStrategy |
| CVE-2026-91941 | 7.5 HIGH | Crawl4AI before 0.9.3 Denial of Service via PDFContentScrapingStrategy |
| CVE-2026-91940 | 7.5 HIGH | crawl4ai before 0.9.3 Arbitrary File Write via PDFContentScrapingStrategy |
| CVE-2026-91944 | 6.1 MEDIUM | crawl4ai before 0.9.3 DOM-based XSS via Playground UI |
No comments yet