Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vx9w-5cx4-9796 | Crawl4AI Has Local File Inclusion in Docker API via file:// URLs |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 12 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote attackers to read arbitrary files from the server filesystem. An attacker can access sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and environment variables via /proc/self/environ, potentially exposing credentials, API keys, and internal application structure. | |
| Title | Crawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-12T15:54:14.790Z
Reserved: 2026-02-11T20:08:07.944Z
Link: CVE-2026-26217
Updated: 2026-02-12T15:54:10.889Z
Status : Received
Published: 2026-02-12T16:16:17.620
Modified: 2026-02-12T16:16:17.620
Link: CVE-2026-26217
No data.
OpenCVE Enrichment
No data.
Github GHSA