CVE-2026-56259
Last modified
CVE-2026-56259 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by supplying a malicious base_url parameter and setting api_token to env:VARIABLE_NAME to exfiltrate provider API keys and server secrets including JWT SECRET_KEY for authentication bypass.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by supplying a malicious base_url parameter and setting api_token to env:VARIABLE_NAME to exfiltrate provider API keys and server secrets including JWT SECRET_KEY for authentication bypass.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kidocode | Crawl4ai | < 0.8.8 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-56259?
How severe is CVE-2026-56259?
How do I fix CVE-2026-56259?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-56253Capgo before 12.128.2 contains an improper access control vu…8.7
- CVE-2026-56254In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, …8.3
- CVE-2026-56255Capgo before 12.128.2 contains a denial of service vulnerabi…5.3
- CVE-2026-56256Capgo before 12.128.2 enforces mandatory two-factor authenti…7.1
- CVE-2026-56257Capgo before 12.128.2 allows direct patching of public.apps.…7.1
- CVE-2026-56258Crawl4AI before 0.8.8 contains an arbitrary file write vulne…9.2
- CVE-2026-5626The Survey Form Block plugin for WordPress is vulnerable to …4.3
- CVE-2026-56260Crawl4AI before 0.8.7 contains an arbitrary file write vulne…9.1
- CVE-2026-56261Crawl4AI before 0.8.7 contains a server-side request forgery…7.5
- CVE-2026-56262Crawl4AI before 0.8.7 contains an authentication bypass vuln…6.5
- CVE-2026-56263Crawl4AI before 0.8.7 contains a stored cross-site scripting…6.1
- CVE-2026-56264Crawl4AI before 0.8.7 contains an arbitrary JavaScript execu…6.1
Are you affected by CVE-2026-56259?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
