CVE-2026-26217: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in unclecode Crawl4AI
Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote attackers to read arbitrary files from the server filesystem. An attacker can access sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and environment variables via /proc/self/environ, potentially exposing credentials, API keys, and internal application structure.
AI Analysis
Technical Summary
CVE-2026-26217 is a critical CWE-22 path traversal vulnerability in unclecode's Crawl4AI product. Versions before 0.8.0 allow unauthenticated remote attackers to exploit the Docker API deployment by supplying file:// URLs to certain endpoints (/execute_js, /screenshot, /pdf, /html). This results in local file inclusion, enabling attackers to read arbitrary files on the server. Sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and /proc/self/environ can be accessed, potentially exposing credentials, API keys, and internal application details. The vulnerability has a CVSS 4.0 score of 9.2, indicating critical severity with network attack vector, no privileges or user interaction required, and high impact on confidentiality and security capabilities.
Potential Impact
An attacker can remotely and without authentication read arbitrary files on the affected server. This includes highly sensitive system files and environment variables that may contain credentials and API keys. The exposure of such information can lead to further compromise of the system or related infrastructure. The vulnerability impacts confidentiality and security capabilities severely, as indicated by the CVSS score.
Mitigation Recommendations
No official patch or fix is currently documented. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the vulnerable endpoints and avoid exposing the Docker API deployment to untrusted networks. Monitor vendor channels for updates and apply any official fixes promptly once released.
CVE-2026-26217: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in unclecode Crawl4AI
Description
Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote attackers to read arbitrary files from the server filesystem. An attacker can access sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and environment variables via /proc/self/environ, potentially exposing credentials, API keys, and internal application structure.
CVSS v4.0
Score 9.2critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-26217 is a critical CWE-22 path traversal vulnerability in unclecode's Crawl4AI product. Versions before 0.8.0 allow unauthenticated remote attackers to exploit the Docker API deployment by supplying file:// URLs to certain endpoints (/execute_js, /screenshot, /pdf, /html). This results in local file inclusion, enabling attackers to read arbitrary files on the server. Sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and /proc/self/environ can be accessed, potentially exposing credentials, API keys, and internal application details. The vulnerability has a CVSS 4.0 score of 9.2, indicating critical severity with network attack vector, no privileges or user interaction required, and high impact on confidentiality and security capabilities.
Potential Impact
An attacker can remotely and without authentication read arbitrary files on the affected server. This includes highly sensitive system files and environment variables that may contain credentials and API keys. The exposure of such information can lead to further compromise of the system or related infrastructure. The vulnerability impacts confidentiality and security capabilities severely, as indicated by the CVSS score.
Mitigation Recommendations
No official patch or fix is currently documented. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the vulnerable endpoints and avoid exposing the Docker API deployment to untrusted networks. Monitor vendor channels for updates and apply any official fixes promptly once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-02-11T20:08:07.944Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 698df67cc9e1ff5ad8e8871a
Added to database: 02/12/2026, 15:49:16 UTC
Last enriched: 07/15/2026, 11:08:33 UTC
Last updated: 08/23/2026, 22:52:09 UTC
Views: 457
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.