crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs…
中危 CVSS 5.4
摘要
crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-7g3g-vhm6-79f3
- https://www.vulncheck.com/advisories/crawl4ai-before-0.9.3-cross-site-scripting-via-innerhtml
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-7g3g-vhm6-79f3
时间线
- nvd_ingest NVD