


Perceptive Security
SOC/SIEM Consultancy

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, whic…
Published:
5 juli 2026 om 22:00:00
Alert date:
6 juli 2026 om 22:02:49
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization, Emerging Technologies
CVE-2026-57572 affects Crawl4AI, an open-source LLM-friendly web crawler and scraper, in versions prior to 0.9.0. The Docker API server accepted user-supplied browser_config.extra_args values that were passed directly into Chromium's launch arguments without sanitization. An attacker could inject malicious Chromium switches combined with --no-zygote to replace the child-process launch command, causing Chromium to fork or execute an attacker-controlled command as the container's runtime user. Because the Docker API is unauthenticated by default, exploitation requires only a single HTTP request, making this trivially exploitable by remote unauthenticated attackers. The vulnerability results in arbitrary command execution within the container environment. The issue has been patched in version 0.9.0 of Crawl4AI.
Technical details
Mitigation steps:
Affected products:
Crawl4AI
Docker API
Chromium
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-57572
https://github.com/unclecode/crawl4ai/commit/60886d1a0c52682e4c83a7cef9dfac417fff6bd2
https://github.com/unclecode/crawl4ai/security/advisories/GHSA-r253-r9jw-qg44
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
