CVE-2026-91943
8.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Summary
Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use DNS rebinding to access internal services, exfiltrating responses through PDF text extraction in crawl results.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| unclecode | crawl4ai | 0 < 0.9.3 | affected |
| unclecode | crawl4ai | 0.9.3 | unaffected |
Weaknesses
- CWE-918: Server-Side Request Forgery (SSRF)
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-q5rj-45vw-vp2g
- https://www.vulncheck.com/advisories/crawl4ai-before-0.9.3-ssrf-via-pdfcontentscrapingstrategy
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.