DOM-based Cross-Site Scripting Vulnerability in crawl4ai by Uncle Code
CVE-2026-91942
5.1MEDIUM
What is CVE-2026-91942?
The crawl4ai application prior to version 0.9.3 features a DOM-based cross-site scripting (XSS) vulnerability within its Docker Playground UI. This vulnerability arises from the mishandling of untrusted crawl results, which are assigned to element.innerHTML. An attacker can exploit this flaw by crafting malicious PDFs that include event-handler markup, leading to unauthorized JavaScript execution within the context of the Playground origin. This execution can result in the theft of API tokens stored in sessionStorage, potentially allowing for authenticated API abuse.
Affected Version(s)
crawl4ai 0 < 0.9.3
crawl4ai 0.9.3
