CVE-2026-56261: Kidocode CRAWL4AI

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. 169.254.169.254), causing the server to make requests to internal services and potentially expose cloud metadata.

Affected products

  • Kidocode CRAWL4AI: before 0.8.7 (fixed in 0.8.7)

Published 2026-07-10. Last modified 2026-07-13.