CVE-2026-56265Disclosure(kidocode / crawl4ai)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kidocode crawl4ai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crawl4ai

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-06-21); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
crawl4ai

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-21: 3Mentions · 2026-08-19: 1Patch / Workaround · 2026-06-21: 2Technical Details · 2026-06-21: 3Technical Details · 2026-08-19: 106-2108-19
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-213
Disclosure1Patch2
2026-08-191
Disclosure1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-56265 - critical 🚨 Crawl4AI < 0.8.7 - Hardcoded JWT Signing Key Authentication Bypass > Crawl4AI Docker API server versions before 0.8.7 ship with a hardcoded default JWT si... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-56265 @pdnuclei #NucleiTemplates...

    Post summary

    The tweet announces CVE-2026-56265 as a critical vulnerability in Crawl4AI Docker API servers, highlighting a hardcoded JWT signing key that allows authentication bypass, but provides no PoC or exploit details.

    00001265
    1.2K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-56265 — CVSS 9.8/10 ██████████ Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/214r6cvIRH

    Post summary

    A critical authentication bypass flaw in Crawl4AI versions before 0.8.7, caused by a hardcoded JWT signing key, has been disclosed with a CVSS score of 9.8/10, and a patch is now available.

    10000236
    59 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56265 Authentication Bypass in Crawl4AI Before 0.8.7 via Hardcoded JWT Signing Key https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56265

    Post summary

    CVE‑2026‑56265 is an authentication bypass vulnerability in Crawl4AI (pre‑0.8.7) that exploits a hardcoded JWT signing key, with no mention of patches, PoC, or active exploitation.

    0000066
    4.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Crawl4AI Authentication Bypass via Hardcoded JWT Signing Key (CVE-2026-56265) Crawl4AI's Docker API server ships with a hardcoded default JWT signing key. Because the secret used to sign authentication tokens is publicly known, any attacker aware of the default key can forge valid JWTs for any user. This lets an unauthenticated remote attacker bypass authentication entirely and gain full access to protected functionality on the API server, with high confidentiality, integrity, and availability impact and no privileges or user interaction required. 👉Upgrade to Crawl4AI 0.8.7.

    Post summary

    Crawl4AI’s API server fails to protect against JWT tampering due to a hardcoded signing key, allowing unauthenticated users to forge tokens. Upgrading to version 0.8.7 mitigates the issue.

    0000075
    223 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkidocodecrawl4ai---

Explore more