crawlab-team has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 9.3 (critical), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.3
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Worst active — by depth score
CVE-2026-90945Critical· 9.8Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables66CVE-2026-75103High· 8.8Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password60
crawlab-team vulnerabilities
CVEs affecting crawlab-team, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-90945Critical· 9.8PoCCrawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrativ…
CVE-2026-75103High· 8.8PoCCrawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and c…