{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/crawl4ai--0.9.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:crawl4ai:crawl4ai:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-91940"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["crawl4ai (\u003c 0.9.3)"],"_cs_severities":["high"],"_cs_tags":["denial-of-service","web-scraping","cve-2026-91941"],"_cs_type":"advisory","_cs_vendors":["crawl4ai"],"content_html":"\u003cp\u003eThe crawl4ai library, specifically in versions prior to 0.9.3, contains an arbitrary file write vulnerability within the PDFContentScrapingStrategy component. The root cause is a failure in the _filter_untrusted_fields function to correctly validate configuration parameters provided during the PDF scraping process. An attacker can craft a malicious configuration body containing a manipulated image_save_dir path. By exploiting this, an attacker can coerce the library to write arbitrary data to locations on the host file system that are accessible to the process running the crawl4ai service. This vulnerability enables attackers to potentially overwrite configuration files, inject malicious scripts, or gain persistence by writing files into sensitive system or application directories, depending on the privileges of the service account.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated or remote attacker to perform arbitrary file writes, potentially leading to remote code execution (RCE) by overwriting executable files or configuration files used by the application or OS. The impact is critical for environments where the crawl4ai library runs with elevated privileges or on sensitive servers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade crawl4ai to version 0.9.3 or later immediately to patch CVE-2026-91940.\u003c/li\u003e\n\u003cli\u003eRun the crawl4ai service under a dedicated, non-privileged service account with restricted file system permissions to limit the impact of potential arbitrary file write exploits.\u003c/li\u003e\n\u003cli\u003eAudit logs for unexpected process activity initiated by the crawl4ai service account, particularly file creation or modification events in directories outside of expected output paths.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T19:42:37Z","date_published":"2026-09-15T17:43:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-91940/","summary":"The PDFContentScrapingStrategy in crawl4ai versions prior to 0.9.3 is vulnerable to arbitrary file write via insufficient input validation in the _filter_untrusted_fields function, allowing attackers to overwrite sensitive files.","title":"Arbitrary File Write Vulnerability in crawl4ai PDFContentScrapingStrategy","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-91940/"}],"language":"en","title":"CraftedSignal Threat Feed - Crawl4ai (\u003c 0.9.3)","version":"https://jsonfeed.org/version/1.1"}