CVE-2026-91940
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| unclecode | crawl4ai | 0.9.0 < 0.9.3 | affected |
| unclecode | crawl4ai | 0.9.3 | unaffected |
Weaknesses
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: partial
Additional References
References
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-xpp7-j28w-2gvx
- https://www.vulncheck.com/advisories/crawl4ai-before-0.9.3-arbitrary-file-write-via-pdfcontentscrapingstrategy
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.