CVE-2026-26217Disclosure(kidocode / crawl4ai)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kidocode crawl4ai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote attackers to read arbitrary files from the server filesystem. An attacker can access sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and environment variables via /proc/self/environ, potentially exposing credentials, API keys, and internal application structure.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crawl4ai

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-12); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
crawl4ai

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-12: 4Mentions · 2026-05-02: 1Mentions · 2026-08-18: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-12: 4Technical Details · 2026-08-18: 102-1205-0208-18
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-124
Disclosure2General1Patch1
2026-05-021
General1
2026-08-181
Disclosure1
Full discourse6 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-26217 - critical 🚨 Crawl4AI < 0.8.0 - Local File Inclusion > The Crawl4AI Docker API endpoints accepted arbitrary URL schemes without an allow-lis... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-26217 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a critical CVE-2026-26217 LFI flaw in Crawl4AI (<0.8.0) that permits arbitrary URL schemes; a link to ProjectDiscovery is provided for further details.

    00011249
    1.2K followersView on X
  • ~lyn@lynettdoteth
    General

    @tiredhungryangr One? CVE-2026-2796, CVE-2026-24881, CVE-2026-24882, CVE-2025-32988, CVE-2025-32989, CVE-2025-64175, CVE-2026-25242, CVE-2026-28357, CVE-2026-28359, CVE-2026-26216, CVE-2026-26217, CVE-2026-25946, CVE-2026-32110, CVE-2026-30930, CVE-2026-30928, CVE-2026-32596...

    Post summary

    The tweet lists multiple CVE identifiers without providing additional context, details, or actionable information.

    10000932
    825 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26217 Local File Inclusion in Crawl4AI Docker API Deployment Before 0.8... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26217 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE-2026-26217, noting it is a Local File Inclusion flaw in Crawl4AI Docker API prior to version 0.8, but it provides no PoC, exploit details, or patch information.

    0001034
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-26217: HIGH] Vulnerability in Crawl4AI &lt; 0.8.0 allows unauthenticated attackers to access sensitive files remotely. Update to version 0.8.0 to secure against potential cyber threats.#cve,CVE-2026-26217,#cybersecurity https://cvefind.com/CVE-2026-26217

    Post summary

    The post alerts users that Crawl4AI versions below 0.8.0 have a high‑severity flaw enabling unauthenticated remote file access and recommends upgrading to version 0.8.0.

    0000039
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26217 - High Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowi... https://www.thehackerwire.com/vulnerability/CVE-2026-26217/ https://t.co/Hvr6yqZwBI

    Post summary

    The text discloses a local file inclusion vulnerability (CVE‑2026‑26217) affecting Crawl4AI versions prior to 0.8.0, detailing the vulnerable Docker API endpoints.

    0000044
    112 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    General

    Security Alert: CVE-2026-26217: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' (CVE-2026-26217) https://radar.offseq.com/threat/cve-2026-26217-cwe-22-improper-limitation-of-a-pat-0f89b04d

    Post summary

    The alert announces CVE-2026-26217, a path traversal vulnerability (CWE-22), and provides a reference link without mentioning any PoC, exploit, or patch.

    0000032
    268 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkidocodecrawl4ai---

Explore more