CVE-2026-56262
Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Produtos afetados
Crawl4AI · Crawl4AIQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →