CVE 9.2 CRITICAL

Crawl4AI – Arbitrary File Write via output_path Symlink and TOCTOU_CVE-2026-56258

9.2 / 10
CRITICAL
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to write files outside the intended directory via symlink and time-of-check-time-of-use (TOCTOU) attacks on the output_path parameter. Remote attackers can exploit insufficient path validation and symlink following to achieve arbitrary file write and potential code execution on systems where the runtime user has write access to executable or cron locations.

AI Analysis

Arbitrary file write vulnerability via output_path symlink and TOCTOU attacks

Basic Information

ID CVE-2026-56258
Source VulnCheck
Published Jun 23, 2026 at 12:12

Affected Product

Vendor Crawl4AI
Product Crawl4AI
Version 0.8.8
Affected Versions Crawl4AI Crawl4AI 0

CWE Classification

AI Assessment

AI Score 9.2 / 10
AI Severity Critical
Vendor Crawl4AI
Product Crawl4AI
Version <0.8.8

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.