By vendor

Kidocode vulnerabilities

Known CVEs affecting Kidocode products, prioritized by severity, with SEC.co remediation and detection guidance.

3 published vulnerabilities

  • CVE-2026-56266HIGH 8.6

    Crawl4AI, a web scraping and content processing tool, contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs. By crafting IPv6-mapped IPv4 addresses, attackers can bypass the application's blocklist protections and reach internal services or cloud metadata endpoints—such as AWS Instance Metadata Service—that should be inaccessible. This affects versions prior to 0.8.7.

  • CVE-2026-56258HIGH 8.1

    Crawl4AI, a web scraping and automation framework, contains a flaw that allows attackers to write files anywhere on a system without authentication. The vulnerability exists in features that take screenshots and generate PDFs. Attackers can exploit this by manipulating file path parameters and using symlinks (shortcuts to files and directories) to bypass safety checks, potentially leading to system compromise if the application runs with elevated privileges.

  • CVE-2026-56263MEDIUM 6.1

    Crawl4AI, a web crawling framework, contains a stored cross-site scripting (XSS) vulnerability in its monitoring dashboard. An attacker can craft a malicious crawl request containing JavaScript code. When a dashboard operator views the crawl results, the malicious code executes in their browser without being sanitized, potentially allowing the attacker to steal session tokens, redirect the operator to phishing sites, or perform actions on their behalf. The vulnerability affects versions prior to 0.8.7.