Vulnerability Description
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-xpp7-j28w-2gvx
- https://www.vulncheck.com/advisories/crawl4ai-before-0.9.3-arbitrary-file-write-
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-xpp7-j28w-2gvx
FAQ
What is CVE-2026-91940?
CVE-2026-91940 is a vulnerability with a CVSS score of 7.5 (HIGH). crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attacke...
How severe is CVE-2026-91940?
CVE-2026-91940 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-91940?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.