CVE-2026-91940
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_unt
Summary
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.
Published 2026-09-15 · first seen here 2026-10-10
Exploit availability
Public exploit code lowers the bar for attackers, so prioritise patching and hunting. These repositories are unverified. Fake PoCs that contain malware are common, so never run them outside an isolated lab.
- BiiTts/CVE-2026-91940-crawl4ai-Arbitrary-File-Write · ★0 · created 2026-10-08
Hunt & detect
Threat hunt brief, Sigma rule and Splunk / Sentinel / CrowdStrike queries are not available for this item yet.