CVE-2026-72904: Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsa...

Added to the CISA Known Exploited Vulnerabilities catalog on 10 Aug 2026. Vendor: AI/ML. Product: LLM.

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe schema dereferencing of user-supplied JSON schemas in apps/api/src/lib/extract/helpers/dereferenc...

Required action: Review and patch if applicable to your AI infrastructure.