Description
crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can inject malicious scripts through crawled page content like the page title to steal the operator's API token from sessionStorage and gain full server control.
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server Compromise via XSS
Action: Immediate Patch
AI Analysis

Impact

Crawl4AI versions prior to 0.9.3 have a DOM‑based cross‑site scripting flaw in the Playground UI. The flawed forceHighlightElement() function writes textContent back to innerHTML, causing JSON responses that contain malicious content to be re‑parsed as HTML. An attacker can inject scripts through crawled page elements such as the page title, which allows the script to read the operator’s API token from sessionStorage and subsequently gain full control of the host that runs Crawl4AI.

Affected Systems

The affected product is the open‑source Crawl4AI tool developed by unclecode. All releases before 0.9.3 are vulnerable. Users running any version of Crawl4AI older than 0.9.3 that exposes the Playground UI are impacted.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. A likely attack vector is an attacker who can influence the content crawled by Crawl4AI so that malicious elements appear in the Playground UI. Once the operator views a compromised page, the injected script can access sessionStorage and compromise the server. The lack of public exploitation data suggests a lower likelihood of attacks at present, but the impact if it occurs is high.

Generated by OpenCVE AI on September 20, 2026 at 16:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Crawl4AI to version 0.9.3 or later, which resolves the DOM‑based XSS flaw.
  • If an upgrade cannot be performed immediately, modify the Playground UI to sanitize any JSON response before rendering, ensuring that textContent is not assigned to innerHTML and that script tags are removed or escaped.
  • Restrict or disable access to the Playground UI for unauthenticated or untrusted users until the vulnerability is remediated.

Generated by OpenCVE AI on September 20, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Unclecode
Unclecode crawl4ai
Vendors & Products Unclecode
Unclecode crawl4ai

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can inject malicious scripts through crawled page content like the page title to steal the operator's API token from sessionStorage and gain full server control.
Title crawl4ai before 0.9.3 DOM-based XSS via Playground UI
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Unclecode Crawl4ai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:28:40.421Z

Reserved: 2026-09-15T11:07:01.913Z

Link: CVE-2026-91944

cve-icon Vulnrichment

Updated: 2026-09-17T19:15:26.803Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:46.433

Modified: 2026-09-17T20:18:54.090

Link: CVE-2026-91944

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')