Loading
🚀🤖 Crawl4AI: Open-source LLM Friendly Web Crawler & scraper
Declares an LLM dependency since 2024-09-25 (version 0.3.0).
Advisories that name crawl4ai as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| GHSA-f989-c77f-r2cq: Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution | High | <= 0.8.7 | 0.8.8 | 2026-06-16 |
| CVE-2026-53754GHSA-4qqr-vv2q-cmr5: Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped) | High | <= 0.8.7 | 0.8.8 | 2026-06-16 |
| GHSA-365w-hqf6-vxfg: Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution | Critical | <= 0.8.6 | 0.8.7 | 2026-06-16 |
As declared in PyPI metadata for version 0.9.4. Optional extras are listed with their extra name.
Among the packages in the registry; not every dependent on PyPI.