Vulnerability Description
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. 169.254.169.254), causing the server to make requests to internal services and potentially expose cloud metadata.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kidocode | Crawl4Ai | < 0.8.7 |
Related Weaknesses (CWE)
References
- https://github.com/unclecode/crawl4aiProduct
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfgMitigationVendor Advisory
- https://www.vulncheck.com/advisories/crawl4ai-server-side-request-forgery-via-weProductThird Party Advisory
FAQ
What is CVE-2026-56261?
CVE-2026-56261 is a vulnerability with a CVSS score of 8.6 (HIGH). Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation...
How severe is CVE-2026-56261?
CVE-2026-56261 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56261?
Check the references section above for vendor advisories and patch information. Affected products include: Kidocode Crawl4Ai.