CVE-2026-56262
MEDIUM
6.5
CVSS 3.1
Description
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.
Metadata
Severity & Metrics
6.5
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Crawl4AI | Crawl4AI | — | 0 < 0.8.7, 0.8.7 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-306 | cna | Missing Authentication for Critical Function |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 6.9 | MEDIUM | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
| 6.5 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
References (3)
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfg https://github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfg
- https://github.com/unclecode/crawl4ai https://github.com/unclecode/crawl4ai
- VulnCheck Advisory: Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server https://www.vulncheck.com/advisories/crawl4ai-unauthenticated-access-to-monitor-endpoints-via-docker-api-server