← voltar
CVE-2026-56262

Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server

CVSS 6.9 MEDIUMEPSS 0.4%CWE-306
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Produtos afetados
Crawl4AI · Crawl4AI

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →