{"data":{"ecosystem":"pypi","name":"crawl4ai","url":"https://aisecwatch.com/packages/pypi/crawl4ai","latestVersion":"0.9.4","firstReleaseAt":"2024-09-25T07:25:49.261Z","repository":"https://github.com/unclecode/crawl4ai","llm":{"exposure":"direct","depth":0,"integratedAt":"2024-09-25T07:25:49.261Z","integratedVersion":"0.3.0","sdks":["huggingface"],"path":[]},"authority":{"profile":["browser","filesystem","http"],"fromDependencies":["pypi:aiofiles","pypi:aiohttp","pypi:httpx","pypi:playwright","pypi:requests","pypi:selenium"]},"dependencies":[{"ecosystem":"pypi","name":"sentence-transformers","versionSpec":null,"scope":"extra:transformer"},{"ecosystem":"pypi","name":"tokenizers","versionSpec":null,"scope":"extra:transformer"},{"ecosystem":"pypi","name":"transformers","versionSpec":null,"scope":"extra:transformer"},{"ecosystem":"pypi","name":"unclecode-litellm","versionSpec":"==1.81.13","scope":"runtime"},{"ecosystem":"pypi","name":"aiofiles","versionSpec":">=24.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"aiohttp","versionSpec":">=3.11.11","scope":"runtime"},{"ecosystem":"pypi","name":"aiosqlite","versionSpec":"~=0.20","scope":"runtime"},{"ecosystem":"pypi","name":"alphashape","versionSpec":">=1.3.1","scope":"runtime"},{"ecosystem":"pypi","name":"anyio","versionSpec":">=4.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"beautifulsoup4","versionSpec":"~=4.12","scope":"runtime"},{"ecosystem":"pypi","name":"brotli","versionSpec":">=1.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"chardet","versionSpec":">=5.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"click","versionSpec":">=8.1.7","scope":"runtime"},{"ecosystem":"pypi","name":"cssselect","versionSpec":">=1.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"fake-useragent","versionSpec":">=2.0.3","scope":"runtime"},{"ecosystem":"pypi","name":"httpx","versionSpec":">=0.27.2","scope":"runtime"},{"ecosystem":"pypi","name":"humanize","versionSpec":">=4.10.0","scope":"runtime"},{"ecosystem":"pypi","name":"lark","versionSpec":">=1.2.2","scope":"runtime"},{"ecosystem":"pypi","name":"lxml","versionSpec":"<7,>=5.3","scope":"runtime"},{"ecosystem":"pypi","name":"nltk","versionSpec":">=3.9.1","scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":"<3,>=1.26.0","scope":"runtime"},{"ecosystem":"pypi","name":"patchright","versionSpec":">=1.49.0","scope":"runtime"},{"ecosystem":"pypi","name":"pillow","versionSpec":">=10.4","scope":"runtime"},{"ecosystem":"pypi","name":"playwright","versionSpec":">=1.49.0","scope":"runtime"},{"ecosystem":"pypi","name":"playwright-stealth","versionSpec":">=2.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"psutil","versionSpec":">=6.1.1","scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":">=2.10","scope":"runtime"},{"ecosystem":"pypi","name":"pyopenssl","versionSpec":">=25.3.0","scope":"runtime"},{"ecosystem":"pypi","name":"pypdf","versionSpec":null,"scope":"extra:pdf"},{"ecosystem":"pypi","name":"python-dotenv","versionSpec":"~=1.0","scope":"runtime"},{"ecosystem":"pypi","name":"pyyaml","versionSpec":">=6.0","scope":"runtime"},{"ecosystem":"pypi","name":"rank-bm25","versionSpec":"~=0.2","scope":"runtime"},{"ecosystem":"pypi","name":"requests","versionSpec":"~=2.26","scope":"runtime"},{"ecosystem":"pypi","name":"rich","versionSpec":">=13.9.4","scope":"runtime"},{"ecosystem":"pypi","name":"scikit-learn","versionSpec":null,"scope":"extra:torch"},{"ecosystem":"pypi","name":"selenium","versionSpec":null,"scope":"extra:sync"},{"ecosystem":"pypi","name":"shapely","versionSpec":">=2.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"snowballstemmer","versionSpec":"~=2.2","scope":"runtime"},{"ecosystem":"pypi","name":"torch","versionSpec":null,"scope":"extra:torch"},{"ecosystem":"pypi","name":"xxhash","versionSpec":"~=3.4","scope":"runtime"}],"advisories":[{"id":"919ed641-a0e7-49df-82cb-cd738b457a8a","url":"https://aisecwatch.com/issues/919ed641-a0e7-49df-82cb-cd738b457a8a","cveId":null,"title":"GHSA-f989-c77f-r2cq: Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution","headline":null,"severity":"high","publishedAt":"2026-06-16T21:00:31.000Z","affected":["crawl4ai@<= 0.8.7 (fixed: 0.8.8)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"e21ef9fd-3db9-4542-b3e6-74ad370e68b5","url":"https://aisecwatch.com/issues/e21ef9fd-3db9-4542-b3e6-74ad370e68b5","cveId":"CVE-2026-53754","title":"GHSA-4qqr-vv2q-cmr5: Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)","headline":null,"severity":"high","publishedAt":"2026-06-16T21:00:04.000Z","affected":["crawl4ai@<= 0.8.7 (fixed: 0.8.8)"],"epssScore":0.00433,"matchedBy":"ecosystem"},{"id":"c9d3a798-39a0-4ef9-b9c0-8ec987f2b685","url":"https://aisecwatch.com/issues/c9d3a798-39a0-4ef9-b9c0-8ec987f2b685","cveId":null,"title":"GHSA-365w-hqf6-vxfg: Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution","headline":null,"severity":"critical","publishedAt":"2026-06-16T20:13:30.000Z","affected":["crawl4ai@<= 0.8.6 (fixed: 0.8.7)"],"epssScore":null,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:58:12.417Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}