10
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.
AI Analysis
Unauthenticated remote code execution vulnerability in Crawl4AI's Docker API deployment via the hooks parameter
Basic Information
ID
CVE-2026-26216
Source
VulnCheck
Published
Feb 12, 2026 at 15:31
Modified
Feb 12, 2026 at 15:45
Affected Product
Vendor
unclecode
Product
Crawl4AI
Affected Versions
unclecode Crawl4AI 0
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
unclecode
Product
Crawl4AI
Version
< 0.8.0