boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-57571CRITICAL
unclecode crawl4ai — Crawl4AI arbitrary file write via download filename path traversal
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0060   45.9     —
AFFECTED
  Product   Versions   Fixed
  crawl4ai  < 0.9.0 –  —
TIMELINE
  Jun 24  Reserved by GitHub_M
  Jul 6   EXPLOIT PUBLISHED — CVE-2026-57571 (unclecode crawl4ai). Public exploit reference added.
  Jul 6   Published (CNA: GitHub_M)
CWE-22, CWE-59 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Analyzed

Description

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path or traversal escaped the downloads directory, giving an arbitrary file write with attacker-controlled contents; the HTTP crawler path uses the response Content-Disposition filename and the browser crawler path uses the download's suggested filename. Because the written bytes are attacker-controlled, this can escalate to remote code execution. This issue is fixed in version 0.9.0.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 24, 2026ReservedReserved by GitHub_M
July 6, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-57571 (unclecode crawl4ai). Public exploit reference added.
July 6, 2026PublishedPublished (CNA: GitHub_M)

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
unclecodecrawl4ai< 0.9.0

Weaknesses

CWE-22 · CWE-59

References (2)

Related

Authoritative record: CVE-2026-57571 at cve.org

Vendors: unclecode

Weaknesses: CWE-22 · CWE-59

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-57571 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.