CVE-2026-57572
CRITICALCrawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
Title source: cnaDescription
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together with --no-zygote, causing Chromium to fork or exec an attacker-controlled command as the container's runtime user. The Docker API is unauthenticated by default, so a single request yields arbitrary command execution. This issue is fixed in version 0.9.0.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/unclecode/crawl4ai/security/advisories/GHSA-r253-r9jw-qg44
X_Refsource_Misc x_refsource_misc
https://github.com/unclecode/crawl4ai/commit/60886d1a0c52682e4c83a7cef9dfac417fff6bd2
Scores
CVSS v3
10.0
EPSS
0.0053
EPSS Percentile
42.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-88
CWE-94
Status
published
Products (2)
kidocode/crawl4ai
< 0.9.0
unclecode/crawl4ai
< 0.9.0
Published
Jul 06, 2026
Tracked Since
Jul 07, 2026