CVE-2026-91944: crawl4ai before 0.9.3 DOM-based XSS via Playground UI

Published Sep 15, 2026
·
Updated

crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can inject malicious scripts through crawled page content like the page title to steal the operator's API token from sessionStorage and gain full server control.

Affected Software

1 affected component
Crawl4AI<0.9.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade crawl4ai to a version that resolves this vulnerability.

    Fixed in 0.9.3
  2. Configuration

    Update crawl4ai to v0.9.3 or later so the Playground UI no longer uses forceHighlightElement() to assign textContent back to innerHTML, which re-parses JSON responses as HTML and enables DOM-based XSS.

    crawl4ai Playground UI forceHighlightElement() handling of JSON responses (textContent assigned back to innerHTML) = Do not assign textContent to innerHTML; prevent re-parsing JSON responses as HTML

Event History

Sep 15, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Operators using the Crawl4AI Playground UI on versions before 0.9.3 are exposed when the UI processes crawled content that an attacker can influence, such as a page title.

2

What does an attacker need to exploit it?

An attacker needs to cause a target operator to use the Playground UI to crawl or process page content containing a malicious payload. No attacker authentication is indicated, but user interaction is required.

3

What can an attacker gain from successful exploitation?

A successful payload can steal the operator's API token from sessionStorage. The provided information states that this can give the attacker full server control.

4

How can this be remediated?

Upgrade Crawl4AI to version 0.9.3 or later. The issue affects versions before 0.9.3.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203