CVE-2024-56800
Last modified
CVE-2024-56800 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions prior to 1.1.1 contain a server-side request forgery (SSRF) vulnerability. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions prior to 1.1.1 contain a server-side request forgery (SSRF) vulnerability. The scraping engine could be exploited by crafting a malicious site that redirects to a local IP address. This allowed exfiltration of local network resources through the API. The cloud service was patched on December 27th, 2024, and the maintainers have checked that no user data was exposed by this vulnerability. Scraping engines used in the open sourced version of Firecrawl were patched on December 29th, 2024, except for the playwright services which the maintainers have determined to be un-patchable. All users of open-source software (OSS) Firecrawl should upgrade to v1.1.1. As a workaround, OSS Firecrawl users should supply the playwright services with a secure proxy. A proxy can be specified through the `PROXY_SERVER` env in the environment variables. Please refer to the documentation for instructions. Ensure that the proxy server one is using is setup to block all traffic going to link-local IP addresses.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-56800?
How severe is CVE-2024-56800?
How do I fix CVE-2024-56800?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-56786Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-56787In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56788In the Linux kernel, the following vulnerability has been re…4.7
- CVE-2024-5679CWE-787: Out-of-Bounds Write vulnerability exists that could…7.1
- CVE-2024-56799Simofa is a tool to help automate static website building an…10
- CVE-2024-5680CWE-129: Improper Validation of Array Index vulnerability ex…5.5
- CVE-2024-56801Tasklists provides plugin tasklists for GLPI. Versions prior…9.8
- CVE-2024-56802Tapir is a private Terraform registry. Tapir versions 0.9.0 …8.7
- CVE-2024-56803Ghostty is a cross-platform terminal emulator. Ghostty, as a…5.1
- CVE-2024-56804An SQL injection vulnerability has been reported to affect V…8.8
- CVE-2024-56805A buffer overflow vulnerability has been reported to affect …5.4
- CVE-2024-56807An out-of-bounds read vulnerability has been reported to aff…5.5
Are you affected by CVE-2024-56800?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
