/Vulnerability Library

crawl4ai < 0.8.9 - Server Side Request Forgery

CVE-2026-53755
Verified

Description

Crawl4AI < 0.8.9 contains a server-side request forgery caused by insufficient SSRF destination checks on proxy addresses in browser and crawler configurations, letting unauthenticated attackers access internal services and cloud metadata endpoints.

Severity

High

CVSS Score

8.2

Published Date

August 6, 2026

Template Author

str4k3r

CVE-2026-53755.yaml
8.2Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE ID:
cwe-918

References

https://github.com/unclecode/crawl4ai/security/advisories/GHSA-6qhc-x826-342c

Remediation Steps

Update to version 0.8.9 or later.