Description
Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use DNS rebinding to access internal services, exfiltrating responses through PDF text extraction in crawl results.
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Server-side request forgery leading to internal network access and data exfiltration
Action: Immediate Patch
AI Analysis

Impact

Crawl4AI versions prior to 0.9.3 have a server‑side request forgery flaw in the PDFContentScrapingStrategy. The _get_pdf_path() function rescues remote files using Python requests without checking the destination URL. This allows an authenticated attacker to point the crawler at URLs that redirect to or use DNS rebinding to resolve to internal addresses. The response contents are then extracted from the PDF text and returned in the crawl results, effectively leaking internal information.

Affected Systems

The affected product is Crawl4AI, specifically all releases before 0.9.3. The CNA vendor is unclecode. No additional affected versions are listed beyond the general pre‑0.9.3 range.

Risk and Exploitability

The vulnerability has a CVSS score of 8.3, indicating high severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. It is not listed in CISA KEV. Based on the description, the likely attack vector is a network request originating from the application to a malicious or redirecting URL that resolves to an internal service. To exploit this, an attacker must have valid authentication to trigger the PDFContentScrapingStrategy and supply a crafted URL; no additional privileges are required beyond authenticated access.

Generated by OpenCVE AI on September 20, 2026 at 16:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Crawl4AI to version 0.9.3 or later, which removes the SSRF in PDFContentScrapingStrategy.
  • Configure the application or network firewall to block outbound HTTP/HTTPS traffic from the crawler to internal IP ranges or restricted hosts.
  • Monitor application logs for anomalous PDF download attempts or internal network requests and alert on suspicious patterns.

Generated by OpenCVE AI on September 20, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Unclecode
Unclecode crawl4ai
Vendors & Products Unclecode
Unclecode crawl4ai

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use DNS rebinding to access internal services, exfiltrating responses through PDF text extraction in crawl results.
Title Crawl4AI before 0.9.3 SSRF via PDFContentScrapingStrategy
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Unclecode Crawl4ai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T16:04:28.656Z

Reserved: 2026-09-15T11:07:01.913Z

Link: CVE-2026-91943

cve-icon Vulnrichment

Updated: 2026-09-15T16:04:22.909Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:46.290

Modified: 2026-09-16T20:17:00.597

Link: CVE-2026-91943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)