Vulnerability Description
crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-7g3g-vhm6-79f3
- https://www.vulncheck.com/advisories/crawl4ai-before-0.9.3-cross-site-scripting-
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-7g3g-vhm6-79f3
FAQ
What is CVE-2026-91942?
CVE-2026-91942 is a vulnerability with a CVSS score of 5.4 (MEDIUM). crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs ...
How severe is CVE-2026-91942?
CVE-2026-91942 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-91942?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.