MEDIUM
CVE-2026-91942
CVSS
5.4
Description
crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.22%
Probability of exploitation in next 30 days
13.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.