Dependency scanning
Check whether crawl4ai is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-56260
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
CVE-2026-56260
Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56260
CVE-2026-56258
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
CVE-2026-53753
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
CVE-2026-53755
Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
CVE-2026-53754
Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)
CVE-2026-56259
Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution
CVE-2026-56259
CVE-2026-56259
CVE-2026-53753
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
CVE-2026-57571
Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE
CVE-2026-57573
Crawl4AI: Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)
CVE-2026-57572
Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
CVE-2026-57573
CVE-2026-57573
CVE-2026-57572
CVE-2026-57572
CVE-2026-57571
CVE-2026-57571
CVE-2025-28197
Crawl4AI SSRF vulnerability
CVE-2025-28197
Crawl4AI SSRF vulnerability
CVE-2026-53755
CVE-2026-53755
CVE-2026-53754
CVE-2026-53754
CVE-2026-56258
CVE-2026-56258
CVE-2026-26216
Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks Parameter
CVE-2026-26217
Crawl4AI Has Local File Inclusion in Docker API via file:// URLs
CVE-2026-26217
CVE-2026-26217
CVE-2026-26216
CVE-2026-26216
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes