{"id":"PYSEC-2026-1281","summary":"Crawl4AI SSRF vulnerability","details":"Crawl4AI \u003c=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.","aliases":["CVE-2025-28197","GHSA-445m-27cf-gr3x"],"modified":"2026-07-07T17:47:33.652480096Z","published":"2026-07-07T16:02:51.277089Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-28197"},{"type":"WEB","url":"https://gist.github.com/AndrewDzzz/f49e79b09ce0643ee1fc2a829e8875e0"},{"type":"PACKAGE","url":"https://github.com/unclecode/crawl4ai"},{"type":"PACKAGE","url":"https://pypi.org/project/crawl4ai"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-445m-27cf-gr3x"}],"affected":[{"package":{"name":"crawl4ai","ecosystem":"PyPI","purl":"pkg:pypi/crawl4ai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.4.247"}]}],"versions":["0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.3.5","0.3.6","0.3.7","0.3.71","0.3.72","0.3.73","0.3.731","0.3.74","0.3.741","0.3.742","0.3.743","0.3.744","0.3.745","0.3.746","0.3.8","0.4.0","0.4.1","0.4.21","0.4.22","0.4.23","0.4.24","0.4.241","0.4.242","0.4.243","0.4.244","0.4.245","0.4.246","0.4.247","0.4.3b1","0.4.3b2","0.4.3b3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/crawl4ai/PYSEC-2026-1281.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}