CVE-2026-56260: Crawl4AI Arbitrary File Write in Docker API
ID: b334b7ad-9713-59c1-96f4-9c2031d2aef1
STIX ID: report--b334b7ad-9713-59c1-96f4-9c2031d2aef1
Feed Name: CosmicBytez Labs
**Executive Summary:** A critical arbitrary file write vulnerability (CVE-2026-56260, CVSS 9.1) in Crawl4AI's Docker API (/screenshot and /pdf endpoints) allows unauthenticated attackers to provide absolute or path-traversal output_path values to write attacker-controlled files to container or mounted host locations, enabling remote code execution, persistence, and host compromise; upgrade to Crawl4AI 0.8.7 and apply recommended mitigations (restrict API access, audit mounts, run non-root, WAF rules).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
