CVE-2026-56260
Critical · CVSS 9.1crawl4ai — Path Traversal Arbitrary File Write
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-22
Description
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.
Search profile — drives PoC discovery
Symbols output_path/screenshot/pdfDocker API serverCWE-22
Keywords CVE-2026-56260crawl4aiarbitrary file writepath traversaloutput_pathscreenshot endpointpdf endpointDocker APIGHSA-365w-hqf6-vxfgcrawl4ai before 0.8.7
Versions: < 0.8.7
Affected packages
| PyPI | crawl4ai | 0 → 0.8.7 |
References
Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z