CVE-2026-56265: Crawl4AI - Authentication Bypass via Hardcoded JWT Signing Key
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56265?
The severity of CVE-2026-56265 is rated critical with a score of 9.8.
What impacts does CVE-2026-56265 have?
CVE-2026-56265 allows attackers to bypass authentication and gain full access to protected functionalities due to a hardcoded JWT signing key.
How do I fix CVE-2026-56265?
To fix CVE-2026-56265, update Crawl4AI to version 0.8.7 or later, which removes the hardcoded JWT signing key.
Who is affected by CVE-2026-56265?
CVE-2026-56265 affects users of Crawl4AI versions prior to 0.8.7.
What type of vulnerability is CVE-2026-56265?
CVE-2026-56265 is an authentication bypass vulnerability due to a hardcoded default JWT signing key.