Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

unclecode — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting unclecode. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This is the vendor-specific vulnerability aggregation page for unclecode. It collects and displays security advisories, bug reports, and known weaknesses affecting unclecode products and services, covering the full documented time range of their public disclosures. Here you can track unclecode's security advisories over time, analyze the distribution of weakness types such as input validation flaws or dependency issues, and review the historical vulnerability record for each specific product in the unclecode portfolio. The page serves as a centralized reference for understanding the security posture of this vendor without requiring external navigation.

Top products by unclecode: Crawl4AI
CVE ID Title CVSS Severity Published
CVE-2026-91944 crawl4ai before 0.9.3 DOM-based XSS via Playground UI — crawl4ai CWE-79 6.1 Medium 2026-09-15
CVE-2026-91943 Crawl4AI before 0.9.3 SSRF via PDFContentScrapingStrategy — crawl4ai CWE-918 7.7 High 2026-09-15
CVE-2026-91941 Crawl4AI before 0.9.3 Denial of Service via PDFContentScrapingStrategy — crawl4ai CWE-400 7.5 High 2026-09-15
CVE-2026-91942 crawl4ai before 0.9.3 Cross-Site Scripting via innerHTML — crawl4ai CWE-79 5.4 Medium 2026-09-15
CVE-2026-91940 crawl4ai before 0.9.3 Arbitrary File Write via PDFContentScrapingStrategy — crawl4ai CWE-22 7.5 High 2026-09-15
CVE-2026-57572 Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args — crawl4ai CWE-88 10.0 Critical 2026-07-06
CVE-2026-57573 Crawl4AI unauthenticated SSRF in Docker streaming crawl endpoint — crawl4ai CWE-918 8.6 High 2026-07-06
CVE-2026-57571 Crawl4AI arbitrary file write via download filename path traversal — crawl4ai CWE-22 9.6 Critical 2026-07-06
CVE-2026-53753 Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API — crawl4ai CWE-94 9.8 Critical 2026-06-23
CVE-2026-53754 Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped) — crawl4ai CWE-918 7.5 High 2026-06-23
CVE-2026-53755 Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check — crawl4ai CWE-918 8.6 High 2026-06-23
CVE-2026-26217 Crawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling — Crawl4AI CWE-22 8.6 High 2026-02-12
CVE-2026-26216 Crawl4AI < 0.8.0 Docker API Unauthenticated Remote Code Execution via Hooks Parameter — Crawl4AI CWE-94 10.0 Critical 2026-02-12

This page lists every published CVE security advisory associated with unclecode. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.