CVE-2026-53755Patch(kidocode / crawl4ai)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch kidocode crawl4ai systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not to the proxy address. An unauthenticated request could supply a proxy pointing at an internal IP and route the browser through it, reaching internal services and cloud-metadata endpoints, while using a perfectly valid crawl URL. The Docker API is unauthenticated by default. /crawl, /crawl/stream, and /crawl/job accept a browser_config (and crawler_config). The following all feed Chromium's egress and were unchecked: browser_config.proxy_config.server, browser_config.proxy (deprecated field), crawler_config.proxy_config.server, and --proxy-server / --proxy-pac-url / --proxy-bypass-list / --host-resolver-rules flags in browser_config.extra_args. This vulnerability is fixed in 0.8.9.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crawl4ai

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-24); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
crawl4ai

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-24: 1Mentions · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-13: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-24: 1Technical Details · 2026-08-13: 106-2408-13
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-241
Patch1
2026-08-131
Disclosure1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-53755 - high 🚨 crawl4ai < 0.8.9 - Server Side Request Forgery > Crawl4AI < 0.8.9 contains a server-side request forgery caused by insufficient SSRF d... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-53755 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a high‑severity SSRF vulnerability in crawl4ai <0.8.9, linking to a library entry with detection details but providing no exploit code or patch information.

    00041270
    1.3K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-53755 - #SSRF in #Crawl4ai #Docker API. Proxy bypass allows access to internal services & cloud metadata. #CVSS 8.6. No patch available. Disable Docker #API or restrict #network access immediately. #CVEAlert #infosec @Docker #devsecops #devops #sysadmin #k8s more: https://www.valtersit.com/cve/CVE-2026-53755

    Post summary

    The tweet alerts about a high-severity SSRF vulnerability (CVE-2026-53755) in Crawl4ai Docker API, noting no patch exists and recommending disabling the Docker API or restricting network access.

    0000067
    962 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkidocodecrawl4ai---

Explore more