Security Credits

September 23, 2026 ยท View on GitHub

We thank the following security researchers for their responsible disclosure:

ResearcherContactVulnerabilityDate Reported
Song Binglin (q1uf3ng)q1uf3ng@proton.meAST sandbox escape via gi_frame.f_back chain (CVSS 9.8)2026-03-29
Jeongbean Jeonwjswjdqls7@gmail.comFile write, SSRF, monitor auth bypass, stored XSS2026-04-13
wulonchiawulonchia@gmail.comFile write via output_path (independent report)2026-04-13
by111 (August829)GitHub: August829Hardcoded JWT secret, eval in /config/dump, /execute_js, hook sandbox escape2026-04-14
secsys_codexsecsys_codex@163.comSSRF via /md, /crawl, /llm endpoints (URL destination validation)2026-04-18
Velayutham SelvarajLinkedInSSRF via missing host validation in validate_url_scheme (independent report)2026-05-06
IcySun & Yashonicysun@qq.com, liyaoyin@qq.comSSRF, file write via output_path, missing auth by default, hook sandbox bypass via asyncio (independent report)2026-05-15
Geo (geo-chen)cve@sageby.comLLM API key exfiltration via unvalidated base_url (0.8.8)2026-06-02
Geo (geo-chen)cve@sageby.comSSRF via proxy_config.server bypassing the SSRF check (0.8.9)2026-06-04
Y4tackery4tacker@gmail.comDownload path traversal -> file write; Chromium launch-arg injection via extra_args (0.9.0)2026-06-18
KOH Jun Sheng (seankohjs)jskoh.2023@scis.smu.edu.sgSSRF on the streaming crawl path /crawl/stream (0.9.0)2026-06-18
UDU_RisePhoGitHub: hoanggxyuukiChromium launch-flag RCE class via extra_args (0.9.0)2026-06-18
Y4tackerGitHub: Y4tackerHook system exec() sandbox escape (MRO chain RCE), Chromium launch-arg injection (--utility-cmd-prefix RCE), HTTP crawler path traversal arbitrary file write2026-07-09
RafaelGitHub: rafaelfiguereod-stackReported SSRF, LLM key exfiltration, and auth gaps (already fixed / not exploitable in current code)2026-07-09
Zhixi "Jace" SunGitHub: manus-useArbitrary file write via unconfined PDFContentScrapingStrategy image-write fields in untrusted config bodies (0.9.3)2026-08-24
Nguyen Tran Thanh LamGitHub: c240030SSRF via PDF download redirects, DoS via unbounded PDF size and page count, XSS via unescaped PDF text in cleaned_html (0.9.3)2026-07-27
e1codesGitHub: e1codesDOM-based XSS in the Docker Playground leading to operator API-token theft (0.9.3)2026-07-24
x0rootGitHub: x0rootSSRF in the hosted service at stage.crawl4ai.com2026-09-02
arpe1618GitHub: arpe1618Blind SSRF via the robots.txt fetch in RobotsParser.can_fetch bypassing the Docker egress controls (0.9.4)2026-09-04
Ibrahim AlJaafreh - Cystack RedTeamLinkedIn, cystack.psSSRF with response disclosure via link_preview_config through the URL seeder (0.9.4)2026-09-04
Adam JordanGitHub: adamyordanUntrusted-config gate bypass via dict-wrapper laundering, leaking server env vars (0.9.4)2026-09-08