CVE-2026-53753: Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes ...
Added to the CISA Known Exploited Vulnerabilities catalog on 23 Jun 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.8.
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f_back, f_builtins...
Required action: Review and patch if applicable to your AI infrastructure.