Server-Side Request Forgery in Jina-AI Reader Crawler Component
CVE-2026-18647

6.9MEDIUM

Key Information:

Vendor

Jina-ai

Status
Vendor
CVE Published:
3 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-18647?

A security vulnerability in the Jina-AI Reader's Crawler component allows for server-side request forgery due to improper validation in the isValidTLD function within the crawler.ts file. This weakness can potentially lead to unauthorized access and exploitation by remote attackers. The flaw was made public, and despite early notification to the vendor, there has been no response regarding a mitigation plan. Given the continuous delivery model of the product, specific versioning details for patched releases remain undisclosed.

Affected Version(s)

reader 1574bfd380d249c86c82db4dace0d9c8fe17e2b1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

orionyan (VulDB User)
VulDB CNA Team
.