Impact
Crawl4AI versions prior to 0.9.3 have a server‑side request forgery flaw in the PDFContentScrapingStrategy. The _get_pdf_path() function rescues remote files using Python requests without checking the destination URL. This allows an authenticated attacker to point the crawler at URLs that redirect to or use DNS rebinding to resolve to internal addresses. The response contents are then extracted from the PDF text and returned in the crawl results, effectively leaking internal information.
Affected Systems
The affected product is Crawl4AI, specifically all releases before 0.9.3. The CNA vendor is unclecode. No additional affected versions are listed beyond the general pre‑0.9.3 range.
Risk and Exploitability
The vulnerability has a CVSS score of 8.3, indicating high severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. It is not listed in CISA KEV. Based on the description, the likely attack vector is a network request originating from the application to a malicious or redirecting URL that resolves to an internal service. To exploit this, an attacker must have valid authentication to trigger the PDFContentScrapingStrategy and supply a crafted URL; no additional privileges are required beyond authenticated access.
OpenCVE Enrichment