Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-57818

Опубликовано: 26 авг. 2025
Источник: nvd
CVSS3: 6.3
EPSS Низкий

Описание

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to version 2.0.1, a server-side request forgery (SSRF) vulnerability was discovered in Firecrawl's webhook functionality. Authenticated users could configure a webhook to an internal URL and send POST requests with arbitrary headers, which may have allowed access to internal systems. This has been fixed in version 2.0.1. If upgrading is not possible, it is recommend to isolate Firecrawl from any sensitive internal systems.

EPSS

Процентиль: 21%
0.00069
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-918

EPSS

Процентиль: 21%
0.00069
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-918