Server-Side Request Forgery in Jina-AI Reader Crawler Component
CVE-2026-18647
Key Information:
Badges
What is CVE-2026-18647?
A security vulnerability in the Jina-AI Reader's Crawler component allows for server-side request forgery due to improper validation in the isValidTLD function within the crawler.ts file. This weakness can potentially lead to unauthorized access and exploitation by remote attackers. The flaw was made public, and despite early notification to the vendor, there has been no response regarding a mitigation plan. Given the continuous delivery model of the product, specific versioning details for patched releases remain undisclosed.
Affected Version(s)
reader 1574bfd380d249c86c82db4dace0d9c8fe17e2b1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
