CVE-2026-32857Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Playwright scraping service where network policy validation is applied only to the initial user-supplied URL and not to subsequent redirect destinations. Attackers can supply an externally valid URL that passes validation and returns an HTTP redirect to an internal or restricted resource, allowing the browser to follow the redirect and fetch the final destination without revalidation, thereby gaining access to internal network services and sensitive endpoints. This issue is distinct from CVE-2024-56800, which describes redirect-based SSRF generally. This vulnerability specifically arises from a post-redirect enforcement gap in implemented SSRF protections, where validation is applied only to the initial request and not to the final redirected destination.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-26); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-26: 2Mentions · 2026-03-29: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-29: 103-2603-29
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-262
Disclosure2
2026-03-291
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32857 Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Playwright scraping service where network policy… https://www.cve.org/CVERecord?id=CVE-2026-32857

    Post summary

    The text references CVE‑2026‑32857, indicating a SSRF protection bypass in Firecrawl’s Playwright scraping service, with no additional exploitation or mitigation details.

    00010182
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32857 - High Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Playwright scraping service where network policy validation is applied on... https://www.thehackerwire.com/vulnerability/CVE-2026-32857/ https://t.co/NnEIuS0Rb7

    Post summary

    The post announces a high‑severity SSRF bypass vulnerability in Firecrawl 2.8.0 and earlier, but does not provide any proof of concept, exploit code, or patch information.

    0000027
    163 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-32857 Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Playwright scraping service where network policy… https://www.cve.org/CVERecord?id=CVE-2026-32857 ----- Traducción: CVE-2026-32857 Fir… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-32857, a SSRF protection bypass vulnerability in Firecrawl's Playwright scraping service, without referencing PoCs, exploits, or patches.

    0000024
    65 followersView on X

Explore more