31 Total advisories
31 Vulnerabilities
0 Malware

Dependency scanning

Check whether crawl4ai is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 9.8
PyPI

CVE-2026-56260

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

CRITICAL 9.8
PyPI

CVE-2026-56260

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

MEDIUM 6.1
PyPI

CVE-2026-56260

CVE-2026-56260

HIGH 8.6
PyPI

CVE-2026-56260

CVE-2026-56260

UNKNOWN
PyPI

CVE-2026-56260

CVE-2026-56260

HIGH 7.5
PyPI

CVE-2026-56260

CVE-2026-56260

UNKNOWN
PyPI

CVE-2026-56260

CVE-2026-56260

UNKNOWN
PyPI

CVE-2026-56260

CVE-2026-56260

MEDIUM 6.5
PyPI

CVE-2026-56260

CVE-2026-56260

HIGH 8.1
PyPI

CVE-2026-56258

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

CRITICAL 9.8
PyPI

CVE-2026-53753

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

HIGH 8.6
PyPI

CVE-2026-53755

Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check

HIGH 7.5
PyPI

CVE-2026-53754

Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)

HIGH 8.2
PyPI

CVE-2026-56259

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

UNKNOWN
PyPI

CVE-2026-56259

CVE-2026-56259

CRITICAL 9.8
PyPI

CVE-2026-53753

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

CRITICAL 9.6
PyPI

CVE-2026-57571

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

HIGH 8.6
PyPI

CVE-2026-57573

Crawl4AI: Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)

CRITICAL 10.0
PyPI

CVE-2026-57572

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

HIGH 8.6
PyPI

CVE-2026-57573

CVE-2026-57573

CRITICAL 10.0
PyPI

CVE-2026-57572

CVE-2026-57572

CRITICAL 9.6
PyPI

CVE-2026-57571

CVE-2026-57571

UNKNOWN
PyPI

CVE-2025-28197

Crawl4AI SSRF vulnerability

UNKNOWN
PyPI

CVE-2025-28197

Crawl4AI SSRF vulnerability

HIGH 7.5
PyPI

CVE-2026-53755

CVE-2026-53755

HIGH 7.5
PyPI

CVE-2026-53754

CVE-2026-53754

UNKNOWN
PyPI

CVE-2026-56258

CVE-2026-56258

UNKNOWN
PyPI

CVE-2026-26216

Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks Parameter

HIGH 8.6
PyPI

CVE-2026-26217

Crawl4AI Has Local File Inclusion in Docker API via file:// URLs

HIGH 7.5
PyPI

CVE-2026-26217

CVE-2026-26217

CRITICAL 10.0
PyPI

CVE-2026-26216

CVE-2026-26216

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes