CVE-2026-56262: Kidocode CRAWL4AI
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.
Affected products
- Kidocode CRAWL4AI: before 0.8.7 (fixed in 0.8.7)
Published 2026-06-24. Last modified 2026-06-26.