CVE-2026-26216Disclosure(kidocode / crawl4ai)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch kidocode crawl4ai systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crawl4ai

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 4 mentions (2026-02-12); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
crawl4ai

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-02-12: 4Mentions · 2026-02-13: 1Mentions · 2026-02-15: 1Mentions · 2026-05-02: 1Mentions · 2026-10-03: 1Exploit Tool / Code · 2026-02-12: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-15: 1Technical Details · 2026-02-12: 4Technical Details · 2026-02-15: 102-1202-1302-1505-0210-03
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-124
Disclosure4
2026-02-131
General1
2026-02-151
Patch1
2026-05-021
General1
Full discourse8 posts
  • pdnuclei-bot@pdnuclei_bot

    🚨 CVE-2026-26216 - critical 🚨 Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Hooks Parameter > Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-26216 @pdnuclei #Nucle...

    00011321
    1.3K followersView on X
  • ~lyn@lynettdoteth
    General

    @tiredhungryangr One? CVE-2026-2796, CVE-2026-24881, CVE-2026-24882, CVE-2025-32988, CVE-2025-32989, CVE-2025-64175, CVE-2026-25242, CVE-2026-28357, CVE-2026-28359, CVE-2026-26216, CVE-2026-26217, CVE-2026-25946, CVE-2026-32110, CVE-2026-30930, CVE-2026-30928, CVE-2026-32596...

    Post summary

    The tweet lists a large number of CVE identifiers with no additional context, technical details, or actionable information.

    10000932
    825 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26216 Remote Code Execution in Crawl4AI Docker API Deployment via Hooks... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26216 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    CVE-2026-26216 is a Remote Code Execution vulnerability in Crawl4AI Docker API deployment via hooks; the text provides basic technical details but no PoC, exploit, patch, or evidence of active exploitation.

    0001042
    4.0K followersView on X
  • Cybersecurity Aide@SecAideInfo
    Patch

    🚨 Alert: A critical RCE vulnerability (CVE-2026-26216) in Crawl4AI (<0.8.0) could be exploited soon! 🚀 Unauthenticated attackers can use the /crawl endpoint to import malicious Python modules via exec(). Act fast to patch and protect your systems! 🔒 #CyberSecurity #CVE

    Post summary

    A critical RCE vulnerability (CVE‑2026‑26216) in Crawl4AI allows unauthenticated attackers to execute arbitrary code via the /crawl endpoint; immediate patching is urged to prevent exploitation.

    0000021
    20 followersView on X
  • VulDB 🛡@vuldb
    General

    We have just added an important vulnerability affecting unclecode Crawl4AI (CVE-2026-26216) https://vuldb.com/?id.345780

    Post summary

    A new vulnerability (CVE-2026-26216) affecting unclecode Crawl4AI has been reported on vuldb, but no further details regarding PoC, exploits, or patches are provided.

    0000066
    2.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26216: CRITICAL] Alert: Crawl4AI < 0.8.0 has a critical remote code execution flaw in its Docker API deployment. Attackers can exploit it to compromise servers, execute commands, access files, and ...#cve,CVE-2026-26216,#cybersecurity https://cvefind.com/CVE-2026-26216

    Post summary

    Crawl4AI versions below 0.8.0 suffer a critical remote code execution vulnerability in their Docker API, enabling attackers to run arbitrary commands and read files on the host. No PoC, exploit tool, patch, or evidence of active exploitation is provided.

    0000053
    583 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL RCE in Crawl4AI <0.8.0 via /crawl endpoint: unauthenticated Python code exec can fully compromise servers. Restrict access, monitor logs, and upgrade ASAP. Full details: https://radar.offseq.com/threat/cve-2026-26216-cwe-94-improper-control-of-generati-09f71e54 #Off... https://t.co/90a1BjxWeq

    Post summary

    The tweet announces a critical unauthenticated remote code execution vulnerability in Crawl4AI versions below 0.8.0 via the /crawl endpoint and urges immediate upgrades and access restrictions.

    0000058
    268 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26216 - Critical Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is e... https://www.thehackerwire.com/vulnerability/CVE-2026-26216/ https://t.co/oZz9tf4fVy

    Post summary

    The text discloses a critical remote code execution vulnerability in Crawl4AI versions prior to 0.8.0, detailing how the /crawl endpoint can be abused via a hooks parameter, but it does not mention a patch, PoC, or active exploitation.

    0000049
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkidocodecrawl4ai---

Explore more