S4E just found a high-severity finding from cve-2025-68645 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2026-26216

10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
crawl4ai
Updated Oct 3, 2026View on NVD →
S4E scanner

CVE history: crawl4ai

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →