Description
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Apply Patch
AI Analysis

Impact

The vulnerability in crawl4ai before 0.9.3 stems from an unvalidated path handling in the PDFContentScrapingStrategy component. The _filter_untrusted_fields function accepts untrusted configuration fields without proper sanitization, allowing attackers to craft image_save_dir paths that point to arbitrary file system locations. Once the service processes the crafted configuration, it writes attacker‑controlled bytes to any directory that the service account can reach, creating the possibility of overwriting critical files, injecting malware, or otherwise compromising the confidentiality, integrity, and availability of affected systems.

Affected Systems

The only vendor/product identified is unclecode’s crawl4ai. Versions earlier than 0.9.3 are affected, as stated in the CVE title and advisory references. No alternative vendors or products appear to be impacted in the supplied data.

Risk and Exploitability

The CVSS score of 8.7 signals a high severity flaw, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers can submit crafted configuration bodies to provoke the write, typically through the service’s API or ingestion mechanism; the likely attack vector thus involves the delivery of malicious configuration data. This flaw permits the creation of arbitrary files or the modification of existing ones wherever the service account has write permission, enabling persistent footholds or escalation opportunities.

Generated by OpenCVE AI on September 20, 2026 at 17:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade crawl4ai to version 0.9.3 or later to resolve the unvalidated path handling flaw.
  • Limit the image_save_dir parameter to a whitelist of safe directories and enforce strict path validation when running crawl4ai, preventing writes to unauthorized locations.
  • Run the crawl4ai service under an account with the minimum necessary permissions to restrict write access to critical system directories and contain any successful arbitrary write attempts.

Generated by OpenCVE AI on September 20, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Unclecode
Unclecode crawl4ai
Vendors & Products Unclecode
Unclecode crawl4ai

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.
Title crawl4ai before 0.9.3 Arbitrary File Write via PDFContentScrapingStrategy
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Unclecode Crawl4ai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T15:47:15.999Z

Reserved: 2026-09-15T11:07:01.912Z

Link: CVE-2026-91940

cve-icon Vulnrichment

Updated: 2026-09-15T15:47:09.235Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:45.460

Modified: 2026-09-16T20:15:36.037

Link: CVE-2026-91940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:15:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')