logo

Critical Arbitrary File Write Vulnerability in Crawl4AI (CVE-2026-56260)

ID: 92aa915a-17e6-5b0d-8482-54fa341f9c9e

STIX ID: report--92aa915a-17e6-5b0d-8482-54fa341f9c9e

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-07-12

Date Updated: 2026-07-18

...
...

CVE-2026-56260 is a critical (CVSS 9.1) arbitrary file-write vulnerability in Crawl4AI < 0.8.7 affecting the Docker API /screenshot and /pdf endpoints, allowing unauthenticated attackers to write files to any location accessible by the application user; users should upgrade to 0.8.7 or later or restrict access to those endpoints to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.