crawlab vulnerabilities
CVEs whose affected-version data names the crawlab package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-90945Critical· 9.8PoCCrawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrativ…
▾ Abyssalcrawlab-team · crawlabEPSS 0.53%via NVD
CVE-2026-75103High· 8.8PoCCrawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and c…
▾ Midnightcrawlab-team · crawlabEPSS 0.34%via NVD