No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unclecode
Unclecode crawl4ai |
|
| Vendors & Products |
Unclecode
Unclecode crawl4ai |
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account. | |
| Title | crawl4ai before 0.9.3 Arbitrary File Write via PDFContentScrapingStrategy | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:47:15.999Z
Reserved: 2026-09-15T11:07:01.912Z
Link: CVE-2026-91940
Updated: 2026-09-15T15:47:09.235Z
Status : Received
Published: 2026-09-15T16:17:45.460
Modified: 2026-09-15T16:17:45.460
Link: CVE-2026-91940
No data.
OpenCVE Enrichment
Updated: 2026-09-15T17:00:12Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')