VulnSea

unclecode has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 7.5 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
5 prev 0

Products

  • crawl4ai 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

unclecode vulnerabilities

CVEs affecting unclecode, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-91941High· 7.5
6d ago

Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service

Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to …

Twilightunclecode · crawl4aiEPSS 0.38%via NVD
CVE-2026-91940High· 7.5PoC
6d ago

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies w…

Midnightunclecode · crawl4aiEPSS 0.42%via NVD
CVE-2026-91944Medium· 6.1
6d ago

crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML

crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can…

Sunlitunclecode · crawl4aiEPSS 0.25%via NVD
CVE-2026-91943High· 7.7PoC
6d ago

Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation

Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs t…

Midnightunclecode · crawl4aiEPSS 0.31%via NVD
CVE-2026-91942Medium· 5.4PoC
6d ago

crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML

crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute …

Twilightunclecode · crawl4aiEPSS 0.22%via NVD
unclecode vulnerabilities (CVEs) · VulnSea