S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-26217 Scanner

CVE-2026-26217 Scanner - Local File Inclusion (LFI) vulnerability in Crawl4AI

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-26217
9.2
CVSScritical
Exploitable remotely over the internet · no authentication required.

Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote attackers to read arbitrary files from the server filesystem. An attacker can access sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and environment variables via /proc/self/environ, potentially exposing credentials, API keys, and internal application structure.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Crawl4AIby unclecode
AFFECTED< 0.8.0SAFE ✓≥ 0.8.0
Updated Sep 9, 2026View on NVD →
Detail

Crawl4AI is utilized by technology specialists and data analysts to efficiently process and index web content through customized scripts. This software is crucial for businesses seeking to analyze web data, understand site structures, and enhance digital presence. Crawl4AI's broad compatibility with various data formats allows it to serve a wide range of industries, including market research and SEO businesses. Many enterprises integrate Crawl4AI into their operational frameworks for robust and adaptable data crawling solutions. The software is specifically designed to manage large datasets while minimizing load times, making it ideal for high-traffic applications. Overall, Crawl4AI offers a flexible and powerful solution for companies aiming to leverage web data.

The Local File Inclusion (LFI) vulnerability present in Crawl4AI allows unauthorized third parties to read files on the local system. This vulnerability is particularly concerning because it permits access without any authentication, which can expose sensitive credentials and configurations. Attackers leverage this vulnerability by crafting special requests using the file:// URL scheme to gain access to the file system. The vulnerability stems from the absence of a strict allow-list validating accepted URL schemes in API endpoints. Users are advised to upgrade to version 0.8.0 or above, where these url scheme validations are enforced. Failure to address this can lead to unwarranted file exposure and security risks.

Technically, the vulnerability is exploited by transmitting an HTTP POST request to specific API endpoints with a crafted JSON payload. The presence of sensitive file data is confirmed upon receiving a 200 HTTP status code along with file content snippets, such as "/etc/passwd." These requests bypass existing security measures due to missing validation of incoming URL schemes. Two primary endpoints identified as vulnerable are '/execute_js' and '/html.' Security researchers discovered that adding proper validations in these endpoints would mitigate the risk of Local File Inclusion successfully. The risk is elevated as the vulnerability is accessible publicly without any authentication barriers.

If exploited, an attacker can read sensitive files, such as password databases or API configuration files, potentially compromising user data and application integrity. This could lead to unauthorized data access, credential theft, or further server-side attacks if critical application files are exposed. Businesses using Crawl4AI might face data breaches, legal implications, and reputational damage if sensitive information is accessed or distributed. As file inclusions are conducted with ease, they pose a substantial threat to the security frameworks ensuring data confidentiality. Organizations could experience significant interruptions or financial loss due to the manipulation of or damage to their data assets.

REFERENCES

Solution Advice
  • Update Crawl4AI to version 0.8.0 or later to ensure URL scheme restrictions are applied.
  • Enhance security monitoring to detect unauthorized access patterns to your endpoints.
  • Conduct regular security audits to identify and rectify potential vulnerabilities.
  • Implement network firewalls to restrict unwanted access to sensitive files.
  • Promote internal policies of security awareness regarding input validation and access controls.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.