© 2025-2026 PySpect
First version without a known vulnerability: 0.9.0
Crawl4AI: Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)
Fixed in: 0.9.0
Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
Fixed in: 0.9.0
Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE
Fixed in: 0.9.0
Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
Fixed in: 0.8.9
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
Fixed in: 0.8.8
Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution
Fixed in: 0.8.8
Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)
Fixed in: 0.8.8
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Fixed in: 0.8.7
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
Fixed in: 0.8.7
Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks Parameter
Fixed in: 0.8.0
Crawl4AI Has Local File Inclusion in Docker API via file:// URLs
Fixed in: 0.8.0
Crawl4AI SSRF vulnerability