Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vx9w-5cx4-9796 | Crawl4AI Has Local File Inclusion in Docker API via file:// URLs |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 20 Feb 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kidocode
Kidocode crawl4ai |
|
| CPEs | cpe:2.3:a:kidocode:crawl4ai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kidocode
Kidocode crawl4ai |
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unclecode
Unclecode crawl4ai |
|
| Vendors & Products |
Unclecode
Unclecode crawl4ai |
Thu, 12 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote attackers to read arbitrary files from the server filesystem. An attacker can access sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and environment variables via /proc/self/environ, potentially exposing credentials, API keys, and internal application structure. | |
| Title | Crawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-12T15:54:14.790Z
Reserved: 2026-02-11T20:08:07.944Z
Link: CVE-2026-26217
Updated: 2026-02-12T15:54:10.889Z
Status : Analyzed
Published: 2026-02-12T16:16:17.620
Modified: 2026-02-20T16:54:08.060
Link: CVE-2026-26217
No data.
OpenCVE Enrichment
Updated: 2026-02-13T21:35:31Z
Github GHSA