crawl4ai < 0.8.9 - Server Side Request Forgery
CVE-2026-53755
Verified
Description
Crawl4AI < 0.8.9 contains a server-side request forgery caused by insufficient SSRF destination checks on proxy addresses in browser and crawler configurations, letting unauthenticated attackers access internal services and cloud metadata endpoints.
Severity
High
CVSS Score
8.2
Published Date
August 6, 2026
Template Author
str4k3r
CVE-2026-53755.yaml
8.2Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE ID:
cwe-918
Remediation Steps
Update to version 0.8.9 or later.