PyPI: crawl4ai
GHSA-r253-r9jw-qg44
Safety vulnerability ID: SFTY-20260618-43123
Affected versions of the Crawl4AI package are vulnerable to Remote Code Execution due to improper handling of Chromium launch arguments. The `browser_config.extra_args` parameter in the `/crawl`, `/crawl/stream`, and `/crawl/job` endpoints allows injection of Chromium switches that can replace child-process launch commands, such as `--utility-cmd-prefix` and `--no-zygote`, leading to the execution of attacker-controlled commands. An attacker can exploit this vulnerability by sending a crafted request to the unauthenticated Docker API server, resulting in arbitrary command execution with the privileges of the container's runtime user, potentially compromising application data and secrets.
Overview
Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
Advisory
Crawl4AI – Argument Injection
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
