PyPI: crawl4ai
GHSA-365w-hqf6-vxfg
Safety vulnerability ID: SFTY-20260616-95092
Affected versions of the Crawl4AI package are vulnerable to Arbitrary File Write due to improper validation of the `output_path` parameter. The `/screenshot` and `/pdf` endpoints accept arbitrary filesystem paths, allowing overwriting of server files or writing to any writable location by the application user. An attacker can exploit this by providing a malicious path to overwrite critical files, potentially leading to Denial of Service (DoS) or unauthorized data manipulation.
Overview
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Advisory
Crawl4AI – Path Traversal
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260616-95092
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfg
- https://nvd.nist.gov/vuln/detail/CVE-2026-56266
- https://github.com/unclecode/crawl4ai
- https://www.vulncheck.com/advisories/crawl4ai-server-side-request-forgery-via-direct-crawl-endpoints
- https://www.vulncheck.com/advisories/crawl4ai-unauthenticated-access-to-monitor-endpoints-via-docker-api-server
- https://www.vulncheck.com/advisories/crawl4ai-stored-cross-site-scripting-in-monitor-dashboard
- https://www.vulncheck.com/advisories/crawl4ai-server-side-request-forgery-via-webhook-urls
- https://www.vulncheck.com/advisories/crawl4ai-authentication-bypass-via-hardcoded-jwt-signing-key
- https://www.vulncheck.com/advisories/crawl4ai-arbitrary-javascript-execution-via-execute-js-endpoint
- https://www.vulncheck.com/advisories/crawl4ai-arbitrary-file-write-via-output-path-parameter
- https://github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-798.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-596.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-3449.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-3443.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-239.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-230.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-229.yaml
- https://github.com/advisories/GHSA-xrfj-6m49-wfmm
- https://github.com/advisories/GHSA-g2pv-76hm-j4x9
- https://github.com/advisories/GHSA-8qrg-7j2f-rf2h
- https://github.com/advisories/GHSA-53rg-46cm-4g2v
- https://github.com/advisories/GHSA-365w-hqf6-vxfg
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
