{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gpt-crawler--1.5.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:builder:gpt-crawler:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-82286"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gpt-crawler (\u003c= 1.5.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","cve","path-traversal"],"_cs_type":"advisory","_cs_vendors":["Builder.io"],"content_html":"\u003cp\u003eCVE-2026-82286 is an arbitrary file write vulnerability affecting gpt-crawler versions up to and including 1.5.1. The flaw exists within the POST /crawl endpoint, which fails to adequately sanitize the 'outputFileName' parameter. An unauthenticated attacker can exploit this lack of validation by supplying crafted input containing path traversal sequences (e.g., ../) or absolute filesystem paths.\u003c/p\u003e\n\u003cp\u003eBy manipulating this parameter, an attacker can influence where the crawler writes its output, enabling the overwriting of critical system files or configuration files with content fetched from attacker-controlled URLs. If successfully exploited, this can lead to remote code execution or system compromise depending on the overwritten target. Defenders should prioritize patching gpt-crawler to a fixed version or restricting access to the /crawl endpoint to authorized users only.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated attacker to achieve arbitrary file writes on the host system. This can lead to system-level configuration changes, the overwriting of binaries, or the placement of malicious web shells. The scope of impact includes any environment where gpt-crawler is deployed with external-facing access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade gpt-crawler to a version beyond 1.5.1 immediately.\u003c/li\u003e\n\u003cli\u003eImplement access control mechanisms to prevent unauthenticated access to the /crawl API endpoint.\u003c/li\u003e\n\u003cli\u003eAudit existing deployments for logs showing unexpected POST requests to /crawl where the 'outputFileName' parameter contains directory traversal characters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:39:26Z","date_published":"2026-08-28T21:39:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gpt-crawler-traversal/","summary":"CVE-2026-82286 is a path traversal vulnerability in gpt-crawler (\u003c= 1.5.1) allowing unauthenticated attackers to perform arbitrary file writes through the /crawl endpoint.","title":"Path Traversal Vulnerability in gpt-crawler via outputFileName Parameter","url":"https://feed.craftedsignal.io/briefs/2026-08-gpt-crawler-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Gpt-Crawler (\u003c= 1.5.1)","version":"https://jsonfeed.org/version/1.1"}