CyberRota Analysis
AI-GeneratedThe Docker Playground UI in crawl4ai versions prior to 0.9.3 is vulnerable to a DOM-based cross-site scripting flaw, allowing attackers to inject malicious JavaScript through crafted PDFs. This can lead to unauthorized access to API tokens stored in sessionStorage, potentially enabling authenticated API abuse. Organizations using affected versions of Java and Docker should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse.