Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vx9w-5cx4-9796 | Crawl4AI Has Local File Inclusion in Docker API via file:// URLs |
Fri, 20 Feb 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kidocode
Kidocode crawl4ai |
|
| CPEs | cpe:2.3:a:kidocode:crawl4ai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kidocode
Kidocode crawl4ai |
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unclecode
Unclecode crawl4ai |
|
| Vendors & Products |
Unclecode
Unclecode crawl4ai |
Thu, 12 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote attackers to read arbitrary files from the server filesystem. An attacker can access sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and environment variables via /proc/self/environ, potentially exposing credentials, API keys, and internal application structure. | |
| Title | Crawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-12T15:54:14.790Z
Reserved: 2026-02-11T20:08:07.944Z
Link: CVE-2026-26217
Updated: 2026-02-12T15:54:10.889Z
Status : Analyzed
Published: 2026-02-12T16:16:17.620
Modified: 2026-02-20T16:54:08.060
Link: CVE-2026-26217
No data.
OpenCVE Enrichment
Updated: 2026-04-18T12:45:45Z
Github GHSA