/Vulnerability Library

Crawl4AI < 0.8.0 - Local File Inclusion

CVE-2026-26217
Verified

Description

The Crawl4AI Docker API endpoints accepted arbitrary URL schemes without an allow-list. An unauthenticated request with a file:// URL could read local files. Fixed in 0.8.0, which restricts accepted URL schemes.

Severity

Critical

Exploit Probability

2%

Published Date

August 5, 2026

Template Author

str4k3r, aryu-ru

CVE-2026-26217.yaml
9.5Severity

CVSS Metrics

CVE ID:
cve-2026-26217

References

https://github.com/unclecode/crawl4ai/security/advisories/GHSA-vx9w-5cx4-9796

Remediation Steps

Update to version 0.8.0 or later.