CVE-2026-56260·Docker vulnerability
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.
- Severity
- critical
- Software
- Docker
- Fixed in
- 0.8.7
- Published
- 2026-07-12
Affected versions
Until: 0.8.7
Fixed in: 0.8.7
How to fix this CVE
Docker users running Crawl4AI versions prior to 0.8.7 should upgrade immediately to patch a critical arbitrary file write vulnerability in the API server's /screenshot and /pdf endpoints. The vulnerability allows remote attackers to write files to arbitrary locations on the host system by manipulating the output_path parameter, potentially leading to data corruption and service disruption. Update Docker and verify Crawl4AI is at version 0.8.7 or later.
sudo dnf update docker-ceDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET /screenshot|/pdf HTTP.*output_path=(?:[a-zA-Z]:\\|/etc/|/root/|/var/www/|\.\.?/)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement strict input validation on the output_path parameter to reject absolute paths (starting with / or drive letters), path traversal sequences (..), and special characters. Whitelist only relative paths within a designated output directory and enforce no symbolic link resolution.How to check if you are affected
- Run 'docker --version' to confirm Docker is installed and check the major version
- Run 'docker inspect $(docker ps -q) | grep -i crawl4ai' to identify if Crawl4AI container is running
- Check Crawl4AI version inside the container: 'docker exec <container_id> pip show crawl4ai | grep Version'
- Verify the fix: Confirm Crawl4AI version is 0.8.7 or later; re-run the pip show command after update
FAQ
What is CVE-2026-56260?
CVE-2026-56260 is a critical arbitrary file write vulnerability in Crawl4AI's Docker API server. The /screenshot and /pdf endpoints fail to validate the output_path parameter, allowing attackers to write files to any location on the host filesystem that the Docker user can access, causing potential data loss and denial of service.
Is CVE-2026-56260 being actively exploited?
No, this vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploit has been released as of now. However, the critical CVSS score and ease of exploitation warrant immediate patching.
What versions of Docker are affected by CVE-2026-56260?
The vulnerability affects Crawl4AI versions before 0.8.7 when deployed via Docker. All versions up to and including 0.8.6 are vulnerable; upgrade to 0.8.7 or later to remediate.
How do I check if my server is vulnerable to CVE-2026-56260?
Identify running Crawl4AI containers with 'docker ps | grep crawl4ai', then run 'docker exec <container_id> pip show crawl4ai | grep Version'. If the version is below 0.8.7, your deployment is vulnerable.
Does Defensia detect CVE-2026-56260?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker and Crawl4AI are installed on a monitored server, CVE-2026-56260 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-56260. Free for 1 server.
Get started free