9.2
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to write files outside the intended directory via symlink and time-of-check-time-of-use (TOCTOU) attacks on the output_path parameter. Remote attackers can exploit insufficient path validation and symlink following to achieve arbitrary file write and potential code execution on systems where the runtime user has write access to executable or cron locations.
AI Analysis
Arbitrary file write vulnerability via output_path symlink and TOCTOU attacks
Basic Information
ID
CVE-2026-56258
Source
VulnCheck
Published
Jun 23, 2026 at 12:12
Affected Product
Vendor
Crawl4AI
Product
Crawl4AI
Version
0.8.8
Affected Versions
Crawl4AI Crawl4AI 0
CWE Classification
AI Assessment
AI Score
9.2 / 10
AI Severity
Critical
Vendor
Crawl4AI
Product
Crawl4AI
Version
<0.8.8