critical CVSS 9.1

CVE-2026-56260·Docker vulnerability

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.

Severity
critical
Software
Docker
Fixed in
0.8.7
Published
2026-07-12

Affected versions

Until: 0.8.7

Fixed in: 0.8.7

How to fix this CVE

Docker users running Crawl4AI versions prior to 0.8.7 should upgrade immediately to patch a critical arbitrary file write vulnerability in the API server's /screenshot and /pdf endpoints. The vulnerability allows remote attackers to write files to arbitrary locations on the host system by manipulating the output_path parameter, potentially leading to data corruption and service disruption. Update Docker and verify Crawl4AI is at version 0.8.7 or later.

sudo dnf update docker-ce

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

POST|GET /screenshot|/pdf HTTP.*output_path=(?:[a-zA-Z]:\\|/etc/|/root/|/var/www/|\.\.?/)

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Implement strict input validation on the output_path parameter to reject absolute paths (starting with / or drive letters), path traversal sequences (..), and special characters. Whitelist only relative paths within a designated output directory and enforce no symbolic link resolution.

How to check if you are affected

  1. Run 'docker --version' to confirm Docker is installed and check the major version
  2. Run 'docker inspect $(docker ps -q) | grep -i crawl4ai' to identify if Crawl4AI container is running
  3. Check Crawl4AI version inside the container: 'docker exec <container_id> pip show crawl4ai | grep Version'
  4. Verify the fix: Confirm Crawl4AI version is 0.8.7 or later; re-run the pip show command after update

FAQ

What is CVE-2026-56260?

CVE-2026-56260 is a critical arbitrary file write vulnerability in Crawl4AI's Docker API server. The /screenshot and /pdf endpoints fail to validate the output_path parameter, allowing attackers to write files to any location on the host filesystem that the Docker user can access, causing potential data loss and denial of service.

Is CVE-2026-56260 being actively exploited?

No, this vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploit has been released as of now. However, the critical CVSS score and ease of exploitation warrant immediate patching.

What versions of Docker are affected by CVE-2026-56260?

The vulnerability affects Crawl4AI versions before 0.8.7 when deployed via Docker. All versions up to and including 0.8.6 are vulnerable; upgrade to 0.8.7 or later to remediate.

How do I check if my server is vulnerable to CVE-2026-56260?

Identify running Crawl4AI containers with 'docker ps | grep crawl4ai', then run 'docker exec <container_id> pip show crawl4ai | grep Version'. If the version is below 0.8.7, your deployment is vulnerable.

Does Defensia detect CVE-2026-56260?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker and Crawl4AI are installed on a monitored server, CVE-2026-56260 will appear in your dashboard with remediation steps.

Related Docker CVEs

CVE-2026-33587CVSS 10Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.
CVE-2026-53576CVSS 10Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a credential check. kestra addresses its resources by URL path segments that the caller chooses (/api/v1/{tenant}/flows/{namespace}, /api/v1/{tenant}/executions/{namespace}/{id}, /api/v1/{tenant}/namespaces/{namespace}/kv/{key}). An anonymous caller picks the literal configs as the final segment, and the request bypasses Basic-Auth entirely. Because the bypass reaches the flow-create and execution-trigger routes, an unauthenticated caller creates a flow containing a Shell or Process task and runs it. The task executes as root inside the kestra container. The official docker-compose.yml mounts /var/run/docker.sock, so root in the container reaches the host Docker daemon. This vulnerability is fixed in 1.0.45 and 1.3.21.
CVE-2026-42298CVSS 10Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a highly privileged GITHUB_TOKEN (write-all permissions). This can be achieved simply by opening a Pull Request from a fork with a maliciously modified Dockerfile.dev. This issue has been patched via commit da44801.
CVE-2026-26216CVSS 10Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.
CVE-2026-40281CVSS 10Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate arguments, allowing injection of arbitrary ExifTool pseudo-tags such as -FileName, -Directory, -SymLink, and -HardLink. This is a bypass of the incomplete key-sanitization fix introduced in v8.30.1. An unauthenticated attacker can rename or move any PDF being processed to an arbitrary path in the container filesystem, overwrite arbitrary files, or create symlinks and hard links at arbitrary paths.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-56260. Free for 1 server.

Get started free