CVE-2026-57571: Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and join...

Added to the CISA Known Exploited Vulnerabilities catalog on 06 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.6.

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path or travers...

Required action: Review and patch if applicable to your AI infrastructure.