Critical severity9.8GHSA Advisory· Published Jun 23, 2026· Updated Jun 29, 2026
CVE-2026-53753
CVE-2026-53753
Description
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f_back, f_builtins) do NOT start with underscore, enabling a complete sandbox escape to achieve arbitrary code execution. The attack requires no authentication (JWT disabled by default) and is triggered via POST /crawl with a crafted extraction schema. This vulnerability is fixed in 0.8.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
crawl4aiPyPI | < 0.8.7 | 0.8.7 |
Affected products
3Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-qxjp-w3pj-48m7ghsaADVISORY
- github.com/unclecode/crawl4ai/security/advisories/GHSA-qxjp-w3pj-48m7nvdThird Party AdvisoryMitigationWEB
- nvd.nist.gov/vuln/detail/CVE-2026-53753ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/crawl4ai/PYSEC-2026-319.yamlghsaWEB
- github.com/unclecode/crawl4ai/pull/1855ghsaWEB
- github.com/unclecode/crawl4ai/pull/1886ghsaWEB
- pypi.org/project/crawl4aighsaWEB
News mentions
0No linked articles in our index yet.