CVE-2026-26216
Last modified
CVE-2026-26216 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). EPSS estimates a 1.59% chance of exploitation in the next 30 days.
Description
Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kidocode | Crawl4ai | < 0.8.0 |
References
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-5882-5rx9-xgxpMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-26216?
How severe is CVE-2026-26216?
How do I fix CVE-2026-26216?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26209cbor2 provides encoding and decoding for the Concise Binary …7.5
- CVE-2026-2621A security vulnerability has been detected in Sciyon Koyuan …7.3
- CVE-2026-26210KTransformers through 0.5.3 contains an unsafe deserializati…9.8
- CVE-2026-26213thingino-firmware versions up to the firmware-2026-03-16 rel…9.8
- CVE-2026-26214Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) versi…9.1
- CVE-2026-26215manga-image-translator version beta-0.3 and prior in shared …9.3
- CVE-2026-26217Crawl4AI versions prior to 0.8.0 contain a local file inclus…7.5
- CVE-2026-26218newbee-mall includes pre-seeded administrator accounts in it…9.8
- CVE-2026-26219newbee-mall stores and verifies user passwords using an unsa…9.3
- CVE-2026-2622A vulnerability was detected in Blossom up to 1.17.1. This v…5.4
- CVE-2026-26220LightLLM version 1.1.0 and prior contain an unauthenticated …9.3
- CVE-2026-26221Hyland OnBase contains an unauthenticated .NET Remoting expo…9.8
Are you affected by CVE-2026-26216?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
