DOM-based XSS Flaw in crawl4ai Affects Data Security
CVE-2026-91944
5.1MEDIUM
What is CVE-2026-91944?
The crawl4ai application versions prior to 0.9.3 are susceptible to a DOM-based cross-site scripting vulnerability in the Playground UI. This security flaw arises from the misuse of the forceHighlightElement() function, which improperly assigns textContent to innerHTML, inadvertently allowing the injection of malicious scripts from crawled page content, including titles. As a result, attackers can exploit this vulnerability to extract sensitive data such as the operator's API token stored in sessionStorage, paving the way for a full compromise of the server.
Affected Version(s)
crawl4ai 0 < 0.9.3
crawl4ai 0.9.3
