VDB
KO

package

PyPI / crawl4ai

pkg:pypi/crawl4ai

CRITICAL 9.8 PyPI
GHSA-365w-hqf6-vxfg

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

Modified: 6/16/2026

HIGH 8.1 PyPI
GHSA-7cx2-g3h9-382p

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

Modified: 6/16/2026

HIGH 8.2 PyPI
GHSA-f989-c77f-r2cq

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

Modified: 6/16/2026