Arbitrary File Write Vulnerability in crawl4ai by UncleCode
CVE-2026-91940
Key Information:
Badges
What is CVE-2026-91940?
The crawl4ai tool prior to version 0.9.3 has a vulnerability where the PDFContentScrapingStrategy's _filter_untrusted_fields function fails to properly validate untrusted configuration fields. This flaw enables attackers to submit specially crafted configuration bodies, potentially containing malicious image_save_dir paths. Consequently, this allows unauthorized writing of attacker-controlled data into any directory that is accessible to the service account, posing significant risks to data security and system integrity.
Affected Version(s)
crawl4ai 0.9.0 < 0.9.3
crawl4ai 0.9.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
