Tag
high
advisory
Crawl4AI Unauthenticated SSRF in Docker API `crawl/stream` Endpoint
2 rules 3 TTPsA remote, unauthenticated attacker can exploit an unpatched Server-Side Request Forgery (SSRF) vulnerability in Crawl4AI Docker API versions up to 0.8.9, specifically targeting the `/crawl/stream` endpoint, to read internal network services and cloud-metadata endpoints, potentially exposing sensitive information like IAM credentials.
crawl4ai
ssrf
web-application
docker
unauthenticated
api-exploitation
2r
3t
high
advisory
PraisonAI Authentication Bypass via PRAISONAI_CALL_AUTH=disabled
2 rules 7 TTPsA high-severity authentication bypass vulnerability in PraisonAI versions prior to 4.6.61 allows unauthenticated attackers to invoke any registered agent by setting the `PRAISONAI_CALL_AUTH=disabled` environment variable, potentially leading to arbitrary code execution or system compromise.
praisonai
web-vulnerability
authentication-bypass
api-exploitation
misconfiguration
container
2r
7t