Intel

AIKIDO-2026-11062

crawl4ai is vulnerable to Code Injection

Code InjectionGHSA-365w-hqf6-vxfg Published Yesterday

98

Critical Risk

This Affects:

PYTHONcrawl4ai
0.0.0 - 0.8.6
Fixed in 0.8.7
Are you affected? Scan for Free

TL;DR

Multiple security vulnerabilities in the Crawl4AI Docker API server affecting endpoints for crawling, markdown/LLM extraction, screenshots, PDFs, webhooks, monitoring, JavaScript execution, and configuration.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

crawl4ai is vulnerable to Code Injection in versions 0.0.0 - 0.8.6.

How to fix this

Upgrade the crawl4ai library to the patch version.