{"id":"CVE-2025-28197","aliases":["GHSA-445m-27cf-gr3x","PYSEC-2026-1281"],"title":"Crawl4AI SSRF vulnerability","summary":"Crawl4AI SSRF vulnerability","severity":"medium","vendor":"crawl4ai","product":"crawl4ai","ecosystem":"pip","affected":["crawl4ai <= 0.4.247"],"published":"2025-04-18","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-445m-27cf-gr3x","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-28197"},{"url":"https://gist.github.com/AndrewDzzz/f49e79b09ce0643ee1fc2a829e8875e0"},{"url":"https://github.com/unclecode/crawl4ai"}],"tags":["osv","pip"],"epss":0.00365,"epssPercentile":0.30395,"ingestedAt":"2026-07-08T18:25:45.245Z","slug":"CVE-2025-28197","body":"## Overview\n\nCrawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.\n\n## Affected packages\n\n- `crawl4ai <= 0.4.247`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}