CVE-2026-26216 is an unauthenticated remote code execution vulnerability affecting Crawl4AI versions prior to 0.8.0 when deployed via its Docker API. The flaw resides in the /crawl endpoint, which accepts a hooks parameter containing Python code that is executed with exec(). The implementation attempted to constrain execution through an allowed builtins list, but it still exposed the import builtin. As a result, a remote attacker can import arbitrary Python modules and execute system-level actions despite the intended restriction. Successful exploitation can lead to complete compromise of the host running the service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained laboratory PoC for CVE-2026-26216 / GHSA-5882-5rx9-xgxp affecting Crawl4AI before 0.8.0. It contains both a vulnerable reproduction and a working exploit. The core issue is unsafe execution of attacker-supplied Python hook code from the unauthenticated POST /crawl endpoint. The vulnerable hook sandbox removes some dangerous builtins but mistakenly leaves __import__ in ALLOWED_BUILTINS, allowing arbitrary imports such as subprocess or os and leading to full sandbox escape and RCE. Repository structure: README.md documents the vulnerability, impact, and usage; docker-compose.yml launches the vulnerable service on port 11235; vulnerable-app/server.py implements a minimal FastAPI server exposing GET /health and POST /crawl; vulnerable-app/hook_manager.py contains the vulnerable exec/compile logic and supported hook events; vulnerable-app/Dockerfile builds a root-running container with example secrets in environment variables; exploit/exploit.py is the main exploit entry point using only Python stdlib. Exploit behavior: exploit/exploit.py builds a malicious hook for the on_page_context_created event, sends it as JSON to /crawl, and retrieves command output from the returned server_log field. The payload imports subprocess via __import__ and runs attacker-controlled shell commands with shell=True. The demo mode shows a blocked naive open('/etc/passwd') attempt, then a successful bypass executing id/whoami/hostname/uname, reading /etc/passwd through the shell, dumping environment variables matching KEY/TOKEN/SECRET, and writing /tmp/PWNED. This is a real exploit, not merely a detector, and it provides practical post-exploitation capability over HTTP without authentication.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated remote code execution vulnerability in Crawl4AI Docker API deployments, affecting versions prior to 0.8.0 via the /crawl hooks parameter, allowing arbitrary command execution and potential full server compromise.
Unauthenticated remote code execution in Crawl4AI (pre-0.8.0) Docker API deployment via the /crawl endpoint hooks parameter, where attacker-supplied Python is executed with exec() and can import modules to run system commands, enabling full server compromise.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.