CyberRota Analysis
AI-GeneratedCrawl4AI versions prior to 0.8.7 contain a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, allowing attackers to exploit unvalidated webhook URLs. This could lead to unauthorized access to internal services and exposure of sensitive cloud metadata, posing a significant risk to environments utilizing Docker. Organizations using affected versions of Crawl4AI should prioritize patching to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. 169.254.169.254), causing the server to make requests to internal services and potentially expose cloud metadata.
Related CVEs
Other vulnerabilities affecting the same vendor(s)