Crawl4AI < 0.8.0 - Local File Inclusion
CVE-2026-26217
Verified
Description
The Crawl4AI Docker API endpoints accepted arbitrary URL schemes without an allow-list. An unauthenticated request with a file:// URL could read local files. Fixed in 0.8.0, which restricts accepted URL schemes.
Severity
Critical
Exploit Probability
2%
Published Date
August 5, 2026
Template Author
str4k3r, aryu-ru
CVE-2026-26217.yaml
9.5Severity
CVSS Metrics
CVE ID:
cve-2026-26217
Remediation Steps
Update to version 0.8.0 or later.