CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-56260

Critical · CVSS 9.1

crawl4ai — Path Traversal Arbitrary File Write

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-22

Description

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.

Search profile — drives PoC discovery

Symbols output_path/screenshot/pdfDocker API serverCWE-22
Keywords CVE-2026-56260crawl4aiarbitrary file writepath traversaloutput_pathscreenshot endpointpdf endpointDocker APIGHSA-365w-hqf6-vxfgcrawl4ai before 0.8.7
Versions: < 0.8.7

Affected packages

PyPI crawl4ai 0 → 0.8.7

References

Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z