generated: '2026-08-29' method: searched source: >- https://github.com/unclecode/crawl4ai/blob/main/SECURITY.md, https://github.com/unclecode/crawl4ai/security/advisories, https://github.com/unclecode/crawl4ai/blob/main/SECURITY-CREDITS.md provider: Crawl4AI providerId: crawl4ai description: >- Crawl4AI runs a real coordinated vulnerability disclosure program with published response SLAs, a preferred private channel, a named security contact set, and a credits file naming external reporters. The program is published in the source repository, NOT as an RFC 9116 /.well-known/security.txt — that path 404s on every Crawl4AI host (probed 2026-08-29). program: present: true type: coordinated-disclosure policy_url: https://github.com/unclecode/crawl4ai/blob/main/SECURITY.md bug_bounty: false bounty_platform: null note: No monetary bounty is offered; credit is the stated reward. channels: - name: GitHub Security Advisories preferred: true url: https://github.com/unclecode/crawl4ai/security/advisories method: Open a new draft security advisory. - name: Email preferred: false address: unclecode@crawl4ai.com cc: - nasrin@crawl4ai.com - aravind@crawl4ai.com subject_convention: '[SECURITY] Brief description' required_content: - Description of the vulnerability - Steps to reproduce - Potential impact - Any suggested fixes prohibited: - Opening a public GitHub issue for a security vulnerability. response_sla: acknowledgment: within 48 hours initial_assessment: within 7 days resolution: critical: 24-72 hours high: 7 days medium: 30 days low: 90 days disclosure_terms: responsible_disclosure: true coordination: 'We will coordinate with you on disclosure timing.' credit: 'Credit will be given to reporters unless anonymity is requested.' cve: 'We may request CVE assignment for significant vulnerabilities.' credits_file: https://github.com/unclecode/crawl4ai/blob/main/SECURITY-CREDITS.md supported_versions: - version: 0.8.x supported: true - version: 0.7.x supported: false note: upgrade recommended - version: '< 0.7' supported: false supported_versions_note: >- This table is out of date — 0.9.x has been the release line since 2026-06-18 and is not listed at all. track_record: advisories_shipped_with_releases: true external_reporters_credited: - Y4tacker - KOH Jun Sheng - 'UDU_RisePho (hoanggxyuuki)' - 'Geo (geo-chen)' recent_cwes_fixed: - CWE-22 (path traversal to file write) - CWE-59 (symlink / TOCTOU) - CWE-93 (webhook header injection) - CWE-94 (Chromium launch-arg injection) - CWE-117 (log injection) - CWE-200 / CWE-522 (LLM credential exfiltration) - CWE-918 (SSRF, three separate fixes) security_txt: served: false probed: - {url: 'https://crawl4ai.com/.well-known/security.txt', status: 404} - {url: 'https://gate.crawl4ai.com/.well-known/security.txt', status: 404} - {url: 'https://docs.crawl4ai.com/.well-known/security.txt', status: 404} - {url: 'https://api.crawl4ai.com/.well-known/security.txt', status: 200, verdict: 'SPA HTML shell, not a document'} recommendation: >- Publish an RFC 9116 security.txt on crawl4ai.com and gate.crawl4ai.com pointing Contact: at unclecode@crawl4ai.com and Policy: at SECURITY.md. The program already exists; only the machine-readable pointer is missing. maintainers: - FN: Kin Lane email: kin@apievangelist.com