Impact
The vulnerability in crawl4ai before 0.9.3 stems from an unvalidated path handling in the PDFContentScrapingStrategy component. The _filter_untrusted_fields function accepts untrusted configuration fields without proper sanitization, allowing attackers to craft image_save_dir paths that point to arbitrary file system locations. Once the service processes the crafted configuration, it writes attacker‑controlled bytes to any directory that the service account can reach, creating the possibility of overwriting critical files, injecting malware, or otherwise compromising the confidentiality, integrity, and availability of affected systems.
Affected Systems
The only vendor/product identified is unclecode’s crawl4ai. Versions earlier than 0.9.3 are affected, as stated in the CVE title and advisory references. No alternative vendors or products appear to be impacted in the supplied data.
Risk and Exploitability
The CVSS score of 8.7 signals a high severity flaw, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers can submit crafted configuration bodies to provoke the write, typically through the service’s API or ingestion mechanism; the likely attack vector thus involves the delivery of malicious configuration data. This flaw permits the creation of arbitrary files or the modification of existing ones wherever the service account has write permission, enabling persistent footholds or escalation opportunities.
OpenCVE Enrichment