logo

CVE-2026-56260: Crawl4AI Arbitrary File Write in Docker API

ID: b334b7ad-9713-59c1-96f4-9c2031d2aef1

STIX ID: report--b334b7ad-9713-59c1-96f4-9c2031d2aef1

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

...
...

**Executive Summary:** A critical arbitrary file write vulnerability (CVE-2026-56260, CVSS 9.1) in Crawl4AI's Docker API (/screenshot and /pdf endpoints) allows unauthenticated attackers to provide absolute or path-traversal output_path values to write attacker-controlled files to container or mounted host locations, enabling remote code execution, persistence, and host compromise; upgrade to Crawl4AI 0.8.7 and apply recommended mitigations (restrict API access, audit mounts, run non-root, WAF rules).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.