PyPI: crawl4ai
CVE-2026-53755
Safety vulnerability ID: SFTY-20260616-98559
Affected versions of the Crawl4AI package are vulnerable to Server-Side Request Forgery (SSRF) due to improper validation of proxy settings in the Docker server. The `/crawl`, `/crawl/stream`, and `/crawl/job` endpoints fail to apply SSRF checks to the `proxy_config.server` field within the `browser_config` and `crawler_config`, allowing requests to be routed through an attacker-specified proxy. An attacker can exploit this by sending requests with a valid crawl URL and a malicious proxy configuration, enabling unauthorized access to internal services and cloud-metadata endpoints, with the responses being returned to the attacker.
Overview
Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
Advisory
Crawl4AI – Server-Side Request Forgery (SSRF)
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260616-98559/CVE-2026-53755
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-6qhc-x826-342c
- https://nvd.nist.gov/vuln/detail/CVE-2026-53755
- https://github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-588.yaml
- https://github.com/advisories/GHSA-6qhc-x826-342c
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
