VYPR

crawlab

by Crawlab Team

CVEs (2)

  • CVE-2026-90945CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.

  • CVE-2026-75103HigAug 17, 2026
    risk 0.57cvss 8.8epss 0.00

    Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve…