PyPI: crawl4ai

GHSA-7cx2-g3h9-382p

Safety vulnerability ID: SFTY-20260616-67050

Affected versions of the Crawl4AI package are vulnerable to Arbitrary File Write due to improper validation of symlink paths. The `POST /screenshot` and `POST /pdf` endpoints accept an `output_path` parameter that was only string-validated against `ALLOWED_OUTPUT_DIR`, allowing symlink traversal to write files outside the intended directory. An attacker can exploit this by crafting a symlink within the allowed directory to a sensitive location, potentially achieving code execution if the runtime user has write permissions to executable directories, as the API is unauthenticated by default.

Created at: Jun 24, 2026Updated at: Jun 24, 2026

Overview

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

Advisory

Crawl4AI – Path Traversal

Affected Package

Affecting crawl4ai package, versions
<= 0.8.7

Also affects

---

How to Fix

Upgrade
crawl4ai
to
0.8.8
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more