CVE-2026-57571Disclosure(kidocode / crawl4ai)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kidocode crawl4ai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path or traversal escaped the downloads directory, giving an arbitrary file write with attacker-controlled contents; the HTTP crawler path uses the response Content-Disposition filename and the browser crawler path uses the download's suggested filename. Because the written bytes are attacker-controlled, this can escalate to remote code execution. This issue is fixed in version 0.9.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-59

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crawl4ai

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-07-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
crawl4ai

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-07: 1Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 107-0707-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-57571 - Critical RCE in #Crawl4AI. Unrestricted file write via path traversal in filename handling. #CVSS 9.6. No patch available. Disable file saving or use sandboxing immediately. #CVEAlerts #infosec #cybersecurity #devsecops #devops  #sysadmin https://www.valtersit.com/cve/CVE-2026-57571/

    Post summary

    The post announces a critical remote code execution flaw (CVE-2026-57571) in Crawl4AI, details its path‑traversal attack vector, notes that no patch exists, and advises disabling file saving or sandboxing the application.

    0001057
    974 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: 2 critical vulnerabilities in #Crawl4ai. #CVE-2026-57572 (CVSS: 10) & #CVE-2026-57571 (CVSS: 9.6). These allow unauthenticated attackers to achieve command injection via the Docker API, leading to #RCE on your device. #Patch #Patch #Patch

    Post summary

    Two critical vulnerabilities in Crawl4ai (CVE-2026-57572 and CVE-2026-57571) allow unauthenticated command injection via Docker API, resulting in RCE, with CVSS scores of 10 and 9.6, and patches are available.

    00000278
    7.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkidocodecrawl4ai---

Explore more