---
id: CVE-2026-26216
title: >-
  Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability
  in the Docker API deployment
summary: >-
  Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability
  in the Docker API deployment. The /crawl endpoint accepts a hooks parameter
  containing Python code that is executed using exec(). The __import__ builtin
  was i…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: kidocode
product: crawl4ai
affected:
  - crawl4ai < 0.8.0
patched:
  - crawl4ai 0.8.0
published: '2026-02-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:11.920'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-26216'
references:
  - url: >-
      https://github.com/unclecode/crawl4ai/blob/main/docs/blog/release-v0.8.0.md
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/unclecode/crawl4ai/security/advisories/GHSA-5882-5rx9-xgxp
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/crawl4ai-docker-api-unauthenticated-remote-code-execution-via-hooks-parameter
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-02-12T21:01:07.012019Z'
epss: 0.05496
epssPercentile: 0.92568
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/joaovicdev/EXPLOIT-CVE-2026-26216'
  nuclei:
    - CVE-2026-26216
  checkedAt: '2026-10-08T16:52:49.760Z'
exploitAvailable: true
ingestedAt: '2026-10-08T16:52:14.672Z'
---

## Overview

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.

## Affected

- `crawl4ai < 0.8.0`

## Remediation

Upgrade past the affected range:

- `crawl4ai 0.8.0`
