Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
unclecode crawl4ai — Crawl4AI arbitrary file write via download filename path traversal
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R C H H H 9.6 .0060 45.9 —
AFFECTED
Product Versions Fixed
crawl4ai < 0.9.0 – —
TIMELINE
Jun 24 Reserved by GitHub_M
Jul 6 EXPLOIT PUBLISHED — CVE-2026-57571 (unclecode crawl4ai). Public exploit reference added.
Jul 6 Published (CNA: GitHub_M)
Description
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path or traversal escaped the downloads directory, giving an arbitrary file write with attacker-controlled contents; the HTTP crawler path uses the response Content-Disposition filename and the browser crawler path uses the download's suggested filename. Because the written bytes are attacker-controlled, this can escalate to remote code execution. This issue is fixed in version 0.9.0.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| June 24, 2026 | Reserved | Reserved by GitHub_M |
| July 6, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-57571 (unclecode crawl4ai). Public exploit reference added. |
| July 6, 2026 | Published | Published (CNA: GitHub_M) |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| unclecode | crawl4ai | — | < 0.9.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-57571 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.