MEDIUM6.5
PYSEC-2026-229
Quick fix
PYSEC-2026-229 — crawl4ai: upgrade to the fixed version with the command below.
pip install --upgrade 'crawl4ai>=0.8.7'Details
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.
Are you affected?
Enter the version of the package you're using.