CVE-2026-56261

Severity CVSS v4.0:
CRITICAL
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
10/07/2026
Last modified:
13/07/2026

Description

Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. 169.254.169.254), causing the server to make requests to internal services and potentially expose cloud metadata.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kidocode:crawl4ai:*:*:*:*:*:*:*:* 0.8.7 (excluding)