22 Total advisories
22 Vulnerabilities
0 Malware

Dependency scanning

Check whether crawl4ai is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 9.8
PyPI

CVE-2026-53753

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

HIGH 8.6
PyPI

CVE-2026-56262

CVE-2026-56262

UNKNOWN
PyPI

CVE-2026-56262

CVE-2026-56262

UNKNOWN
PyPI

CVE-2026-56262

CVE-2026-56262

MEDIUM 6.5
PyPI

CVE-2026-56262

CVE-2026-56262

CRITICAL 9.8
PyPI

CVE-2026-56262

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

HIGH 7.5
PyPI

CVE-2026-53754

Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)

HIGH 8.6
PyPI

CVE-2026-53755

Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check

HIGH 7.5
PyPI

CVE-2026-53755

CVE-2026-53755

HIGH 7.5
PyPI

CVE-2026-53754

CVE-2026-53754

CRITICAL 9.8
PyPI

CVE-2026-53753

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

HIGH 8.1
PyPI

CVE-2026-56258

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

UNKNOWN
PyPI

CVE-2026-56258

CVE-2026-56258

CRITICAL 9.6
PyPI

GHSA-2jq4-q6vv-4cp3

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

CRITICAL 10.0
PyPI

GHSA-r253-r9jw-qg44

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

HIGH 8.6
PyPI

GHSA-wm69-2pc3-rmmf

Crawl4AI: Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)

HIGH 8.2
PyPI

GHSA-f989-c77f-r2cq

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

UNKNOWN
PyPI

CVE-2026-26216

Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks Parameter

HIGH 8.6
PyPI

CVE-2026-26217

Crawl4AI Has Local File Inclusion in Docker API via file:// URLs

HIGH 7.5
PyPI

CVE-2026-26217

CVE-2026-26217

CRITICAL 10.0
PyPI

CVE-2026-26216

CVE-2026-26216

UNKNOWN
PyPI

CVE-2025-28197

Crawl4AI SSRF vulnerability

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes