PYPI · JUNE 2026 · EARLY WARNING

Crawl4AI Package Vulnerability: AST Sandbox Escape Threat

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-QXJP-W3PJ-48M7Severity: HIGH

An early warning has been issued regarding a potential vulnerability in the Crawl4AI package that could enable arbitrary code execution through an AST sandbox escape.

What happened

Reports indicate that the `_safe_eval_expression()` function in the computed fields feature of the Crawl4AI package may have a critical flaw. The AST validator used in this function appears to inadequately block certain attributes, potentially allowing a complete sandbox escape. This could result in arbitrary code execution under certain conditions.

The vulnerability is reported to affect multiple versions of the crawl4ai package, from the initial release up to version 0.8.9. The issue has been addressed in version 0.9.0. It is recommended to upgrade to this version to mitigate the risk.

Additionally, enabling JWT authentication via the `CRAWL4AI_API_TOKEN` environment variable is advised as a supplementary security measure. Users should consult the primary sources for detailed version information and further instructions on securing their environments.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If crawl4ai is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats