Signal is active with 1 mentions in latest observed window
Immediate actions
Patch kidocode crawl4ai systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. 169.254.169.254), causing the server to make requests to internal services and potentially expose cloud metadata.
🚨Critical - Crawl4AI SSRF via Unvalidated Webhook URLs (CVE-2026-56261)
Crawl4AI's Docker API server accepts webhook URLs in its /crawl/job and /llm/job endpoints without validating the destination. An attacker can point a webhook at private/internal IP ranges, Docker networks, or cloud metadata endpoints (169.254.169.254), making the server issue requests to internal services.
That enables reaching internal APIs and exposing cloud metadata credentials - high confidentiality impact with a scope change. It's one of several issues consolidated in the Crawl4AI advisory (GHSA-365w-hqf6-vxfg), all fixed in 0.8.7.
👉Upgrade Crawl4AI to 0.8.7.
Post summary
The advisory highlights a critical SSRF flaw in Crawl4AI's webhook handling and urges users to upgrade to version 0.8.7 to eliminate the vulnerability.