VulnWatch VulnWatch
← Back to dashboard
Critical nvd · CVE-2026-56266

CVE-2026-56266: Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm e

Published Jun 22, 2026 CVSS 9.2

Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services and cloud metadata endpoints.

Affected AI Products

llm
Get the weekly digest. Every Monday: top AI security stories of the week. Free.