CVE-2026-53754: Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination in deploy/docker/utils.py) us...

Added to the CISA Known Exploited Vulnerabilities catalog on 23 Jun 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.5.

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination in deploy/docker/utils.py) used an explicit IPv4/IPv6 CIDR blocklist that missed several address families. An attacker could reac...

Required action: Review and patch if applicable to your AI infrastructure.