No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unclecode
Unclecode crawl4ai |
|
| Vendors & Products |
Unclecode
Unclecode crawl4ai |
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can inject malicious scripts through crawled page content like the page title to steal the operator's API token from sessionStorage and gain full server control. | |
| Title | crawl4ai before 0.9.3 DOM-based XSS via Playground UI | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:18:03.786Z
Reserved: 2026-09-15T11:07:01.913Z
Link: CVE-2026-91944
No data.
Status : Awaiting Analysis
Published: 2026-09-15T16:17:46.433
Modified: 2026-09-16T20:15:36.037
Link: CVE-2026-91944
No data.
OpenCVE Enrichment
Updated: 2026-09-16T03:15:06Z