top of page
perceptive_background_267k.jpg

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, whic…

Published:

5 juli 2026 om 22:00:00

Alert date:

6 juli 2026 om 22:02:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Cloud & Virtualization, Emerging Technologies

CVE-2026-57572 affects Crawl4AI, an open-source LLM-friendly web crawler and scraper, in versions prior to 0.9.0. The Docker API server accepted user-supplied browser_config.extra_args values that were passed directly into Chromium's launch arguments without sanitization. An attacker could inject malicious Chromium switches combined with --no-zygote to replace the child-process launch command, causing Chromium to fork or execute an attacker-controlled command as the container's runtime user. Because the Docker API is unauthenticated by default, exploitation requires only a single HTTP request, making this trivially exploitable by remote unauthenticated attackers. The vulnerability results in arbitrary command execution within the container environment. The issue has been patched in version 0.9.0 of Crawl4AI.

Technical details

Mitigation steps:

Affected products:

Crawl4AI
Docker API
Chromium

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page