CVE-2025-28197: Kidocode CRAWL4AI
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.
Affected products
- Kidocode CRAWL4AI: up to and including 0.4.247
Published 2025-04-18. Last modified 2026-06-17.