Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2pv-76hm-j4x9

Опубликовано: 01 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied JavaScript in the server's browser context with --disable-web-security enabled. An attacker can execute arbitrary JavaScript and, combined with the browser's relaxed security settings, perform server-side request forgery against internal services.

Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied JavaScript in the server's browser context with --disable-web-security enabled. An attacker can execute arbitrary JavaScript and, combined with the browser's relaxed security settings, perform server-side request forgery against internal services.

EPSS

Процентиль: 40%
0.00488
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.1
nvd
2 месяца назад

Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied JavaScript in the server's browser context with --disable-web-security enabled. An attacker can execute arbitrary JavaScript and, combined with the browser's relaxed security settings, perform server-side request forgery against internal services.

EPSS

Процентиль: 40%
0.00488
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-94