CVE-2026-56266: Kidocode CRAWL4AI

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services and cloud metadata endpoints.

Affected products

  • Kidocode CRAWL4AI: before 0.8.7 (fixed in 0.8.7)

Published 2026-06-22. Last modified 2026-06-30.