HIGH 8.7 NVD
CVE-2026-91940
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.
References
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-xpp7-j28w-2gvx
- https://www.vulncheck.com/advisories/crawl4ai-before-0.9.3-arbitrary-file-write-via-pdfcon
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-xpp7-j28w-2gvx
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-15 via NVD.
vulnfeed aggregates 13549 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.