DOM-based Cross-Site Scripting Vulnerability in crawl4ai by Uncle Code
CVE-2026-91942

5.1MEDIUM

Key Information:

Vendor

Unclecode

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91942?

The crawl4ai application prior to version 0.9.3 features a DOM-based cross-site scripting (XSS) vulnerability within its Docker Playground UI. This vulnerability arises from the mishandling of untrusted crawl results, which are assigned to element.innerHTML. An attacker can exploit this flaw by crafting malicious PDFs that include event-handler markup, leading to unauthorized JavaScript execution within the context of the Playground origin. This execution can result in the theft of API tokens stored in sessionStorage, potentially allowing for authenticated API abuse.

Affected Version(s)

crawl4ai 0 < 0.9.3

crawl4ai 0.9.3

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

c240030
.