crawl4ai is vulnerable to Code Injection
98
Critical Risk
The _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f_back, f_builtins) do NOT start with underscore, enabling a complete sandbox escape to achieve arbitrary code execution.
You are affected if you are using a version that falls within the vulnerable range.
crawl4ai is vulnerable to Code Injection in versions 0.0.0 - 0.8.6.
Upgrade the crawl4ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant