Skip to main content

Go to Calendar     Go to Press Room     Go to Newsletters subscription

  • INCIBE
    • Your Help in Cybersecurity
      • FAQ
    • Training
    • Cibercooperantes Program
    • Press Room
    • Corporate information
      • What is INCIBE
          1. Organisation chart
          2. Internal regulations
      • What we do
      • How do we operate
      • Who we work with
          1. European projects participation
          2. Memberships
          3. Network of excellence on cybersecurity R&D&i
          4. Companies
      • Contracting Organisation Profile
      • Calendar
  • INCIBE-CERT
    • Early Warning
      • Security Advisories
      • ICS Advisories
      • Vulnerabilities
          1. CNA
          2. CVE assignment and publication
          3. Coordinated CVEs
          4. Participating CNAs
    • Blog
    • Publications
      • Cybersecurity Highlights
      • Guides
      • Webinars
      • Segmented
    • Incidents
      • Incident responses
    • Services
    • About us
      • What is INCIBE-CERT
      • PGP Public keys
      • TLP
      • Vulnerability disclosure policy
      • RFC 2350
  • CITIZENS
    • Seniors
    • We help you
      • Tu Ayuda en Ciberseguridad
      • Reporte de fraude
    • Security tools
    • Temáticas
  • MINORS
    • Educators
    • Families
      • Parental Mediation
      • Cybersecurity
    • Youth
    • Hotline
  • Companies
    • We help you
      • Tu Ayuda en Ciberseguridad
    • TemáTICas
  • EVENTS
    • SID
    • Cybersecurity Summer BootCamp
    • ENISE
    • CyberCamp
  • DIGITAL SPAIN 2026
    • Cybersecurity Entrepreneurship
    • NCC-ES INCIBE
    • Internationalization
      • New Markets
      • Exterior Visibility
      • Foreign Investment
 
Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT
  • INCIBE
    •  
    • Your Help in Cybersecurity
      •  
      • FAQ
    • Training
    • Cibercooperantes Program
    • Press Room
    • Corporate information
      •  
      • What is INCIBE
        •  
          1. Organisation chart
          2. Internal regulations
      • What we do
      • How do we operate
      • Who we work with
        •  
          1. European projects participation
          2. Memberships
          3. Network of excellence on cybersecurity R&D&i
          4. Companies
      • Contracting Organisation Profile
      • Calendar
  • INCIBE-CERT
    •  
    • Early Warning
      •  
      • Security Advisories
      • ICS Advisories
      • Vulnerabilities
        •  
          1. CNA
          2. CVE assignment and publication
          3. Coordinated CVEs
          4. Participating CNAs
    • Blog
    • Publications
      •  
      • Cybersecurity Highlights
      • Guides
      • Webinars
      • Segmented
    • Incidents
      •  
      • Incident responses
    • Services
    • About us
      •  
      • What is INCIBE-CERT
      • PGP Public keys
      • TLP
      • Vulnerability disclosure policy
      • RFC 2350
  • CITIZENS
    •  
    • Seniors
    • We help you
      •  
      • Tu Ayuda en Ciberseguridad
      • Reporte de fraude
    • Security tools
    • Temáticas
  • MINORS
    •  
    • Educators
    • Families
      •  
      • Parental Mediation
      • Cybersecurity
    • Youth
    • Hotline
  • Companies
    •  
    • We help you
      •  
      • Tu Ayuda en Ciberseguridad
    • TemáTICas
  • EVENTS
    •  
    • SID
    • Cybersecurity Summer BootCamp
    • ENISE
    • CyberCamp
  • DIGITAL SPAIN 2026
    •  
    • Cybersecurity Entrepreneurship
    • NCC-ES INCIBE
    • Internationalization
      •  
      • New Markets
      • Exterior Visibility
      • Foreign Investment

Go to Calendar     Go to Press Room     Go to Newsletters subscription

Search

  1. Home
  2. INCIBE-CERT
  3. Early warning
  4. Vulnerabilities
  5. CVE-2025-28197

CVE-2025-28197

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
18/04/2025
Last modified:
22/04/2025

Description

Crawl4AI

Impact

Vector 3.x
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS v3.1 Severity and Metrics:

Base Score: 9.10 CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope (S): Unchanged
Confidentiality (C): High
Integrity (I): High
Availability (A): None

Base Score 3.x
9.10
Severity 3.x
CRITICAL

References to Advisories, Solutions, and Tools

  • https://gist.github.com/AndrewDzzz/f49e79b09ce0643ee1fc2a829e8875e0
INCIBE-CERT

Newsletter subscription

Nipo: 094-20-022-9

Follow us:  Link to INCIBE-CERT's Twitter Link to INCIBE-CERT's Linkedin Link to INCIBE-CERT's YouTube account

  • Contact
  • Personal Data Protection Policy
  • Legal notice
  • Configure cookies
  • Cookies policy
  • Site Map
  • Contracting Organisation Profile

Funded by the European Union - Next Generation EU

 

Government of Spain. Ministry for digital transformation and public service. Secretary of state for for Telecommunications and Digital Infrastructures

Recovery, Transformation and Resilience Plan

 

Conformity Certification
Aenor Security Information
Aenor Registered Company

Nipo: 094-20-027-6

INCIBE on Twitter INCIBE on Instagram INCIBE on Linkedin INCIBE on Facebook INCIBE on YouTube

×

imagen ampliada

Go top