Impact
Crawl4AI versions prior to 0.9.3 have a DOM‑based cross‑site scripting flaw in the Playground UI. The flawed forceHighlightElement() function writes textContent back to innerHTML, causing JSON responses that contain malicious content to be re‑parsed as HTML. An attacker can inject scripts through crawled page elements such as the page title, which allows the script to read the operator’s API token from sessionStorage and subsequently gain full control of the host that runs Crawl4AI.
Affected Systems
The affected product is the open‑source Crawl4AI tool developed by unclecode. All releases before 0.9.3 are vulnerable. Users running any version of Crawl4AI older than 0.9.3 that exposes the Playground UI are impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. A likely attack vector is an attacker who can influence the content crawled by Crawl4AI so that malicious elements appear in the Playground UI. Once the operator views a compromised page, the injected script can access sessionStorage and compromise the server. The lack of public exploitation data suggests a lower likelihood of attacks at present, but the impact if it occurs is high.
OpenCVE Enrichment