GHSA-5882-5rx9-xgxp · Severity: critical · Ecosystem: pip — Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks Parameter
Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.
Conclusion & alert: CVE-2026-26216 is rated Moderate Risk (50.8/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.13%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-22 | 0.27% | 0.13% | -0.14% |
| 2 | 2026-02-18 | 0.20% | 0.27% | +0.06% |
| 3 | 2026-02-13 | — | 0.20% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 10.0 | 4.0 | CRITICAL |
|
— | — | [email protected] |
| 10.0 | 3.1 | CRITICAL |
|
3.9 | 6.0 | [email protected] |
GHSA-5882-5rx9-xgxp · Severity: critical · Ecosystem: pip — Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks Parameter
| URL | Tags |
|---|---|
| https://github.com/unclecode/crawl4ai/blob/main/docs/blog/release-v0.8.0.md | Release Notes |
| https://github.com/unclecode/crawl4ai/security/advisories/GHSA-5882-5rx9-xgxp | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/crawl4ai-docker-api-unauthenticated-remote-code-execution-via-hooks-parameter | Third Party Advisory |