Description
crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse.
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Theft
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a DOM‑based cross‑site scripting flaw in the Docker Playground UI of crawl4ai. Untrusted crawl results are assigned directly to an element’s innerHTML, allowing attackers to inject malicious JavaScript. When a victim opens a crafted PDF containing event‑handler markup, the script runs in the Playground origin and can read tokens stored in sessionStorage, enabling unauthorized API calls at the victim’s credential level.

Affected Systems

The affected product is crawl4ai, developed by unclecode, in all releases prior to version 0.9.3. No further product or version granularity is provided in the data.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of active exploitation. Attackers would need to lure a user into opening the Docker Playground UI and triggering the embedded malicious script via a PDF file, making the vector impact limited to the current session’s authentication context, but it permits exploitation of the victim’s API tokens.

Generated by OpenCVE AI on September 20, 2026 at 16:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade crawl4ai to version 0.9.3 or later to remove the DOM‑based XSS flaw.
  • Limit or disable access to the Docker Playground UI for users who do not require it, restricting the attack surface.
  • Sanitize all data before inserting into innerHTML—use textContent or a safe rendering library—to prevent arbitrary script execution.

Generated by OpenCVE AI on September 20, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Unclecode
Unclecode crawl4ai
Vendors & Products Unclecode
Unclecode crawl4ai

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse.
Title crawl4ai before 0.9.3 Cross-Site Scripting via innerHTML
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Unclecode Crawl4ai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:51:56.078Z

Reserved: 2026-09-15T11:07:01.913Z

Link: CVE-2026-91942

cve-icon Vulnrichment

Updated: 2026-09-17T14:51:49.947Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:46.150

Modified: 2026-09-17T15:16:57.450

Link: CVE-2026-91942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')