/Vulnerability Library

Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Hooks Parameter

CVE-2026-26216
Verified

Description

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.

Severity

Critical

CVSS Score

10

Exploit Probability

5%

Published Date

October 2, 2026

Template Author

dishantmodi

CVE-2026-26216.yaml
10.0Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-26216
CWE ID:
cwe-94

References

https://github.com/unclecode/crawl4ai/security/advisories/GHSA-5882-5rx9-xgxphttps://www.vulncheck.com/advisories/crawl4ai-docker-api-unauthenticated-remote-code-execution-via-hooks-parameterhttps://github.com/unclecode/crawl4ai/blob/main/docs/blog/release-v0.8.0.mdhttps://nvd.nist.gov/vuln/detail/CVE-2026-26216

Remediation Steps

Upgrade to Crawl4AI 0.8.0 or later, which removes __import__ from allowed_builtins in hook_manager.py and disables hooks by default (CRAWL4AI_HOOKS_ENABLED=false). As an interim mitigation, disable the Docker API deployment or restrict network access to it and add authentication.