AUGUST 27, 2026
Live Feed
Back to database
Case File

CVE-2026-56259

HIGH · CVSS 8.2 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-12 · Last synced 2026-08-11

CyberRota Analysis

AI-Generated

Crawl4AI versions prior to 0.8.8 are vulnerable due to credential exfiltration flaws in the Docker API server, enabling attackers to redirect API calls and access sensitive environment variables. Exploiting unauthenticated endpoints allows for the extraction of critical secrets, including API keys and JWT secret keys, potentially leading to authentication bypass. Organizations using affected versions of Crawl4AI should prioritize immediate updates to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56259
Severity
HIGH
CVSS
8.2
EPSS
0.31%
Docker

Original NVD Description

Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by supplying a malicious base_url parameter and setting api_token to env:VARIABLE_NAME to exfiltrate provider API keys and server secrets including JWT SECRET_KEY for authentication bypass.

Related CVEs

Other vulnerabilities affecting the same vendor(s)