SSRF Vulnerability in Crawl4AI by AndrewDzzz
CVE-2025-28197
9.1CRITICAL
What is CVE-2025-28197?
Crawl4AI versions prior to 0.4.247 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. This issue arises in the async_dispatcher.py file, allowing attackers to send unauthorized requests to internal services, which can lead to unauthorized access to sensitive data or systems. Organizations using vulnerable versions of Crawl4AI should promptly assess their security posture and apply necessary patches to mitigate this risk.
