Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs and error messages via innerHTML without escaping. An attacker can submit a crafted crawl request with malicious markup that executes in an operator's browser when viewing the dashboard.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs and error messages via innerHTML without escaping. An attacker can submit a crafted crawl request with malicious markup that executes in an operator's browser when viewing the dashboard. | |
| Title | Crawl4AI - Stored Cross-Site Scripting in Monitor Dashboard | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-23T12:13:00.000Z
Reserved: 2026-06-20T01:42:20.615Z
Link: CVE-2026-56263
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-23T13:30:03Z