Tags: unclecode/crawl4ai
Tags
v0.9.4: security release Closes three coordinated-disclosure advisories in the Docker server's egress controls and untrusted-config gate. GHSA-f77g-77vp-r96v blind SSRF via the robots.txt fetch GHSA-wh5w-hmj3-vgg7 SSRF with response disclosure via link preview GHSA-5w5p-vcv6-mm3f untrusted-config gate bypass leaking env vars Also adds PruningContentFilterLXML, about 10x faster pruning, now the default. No breaking changes.
docs: release notes, changelog, README, and security credits for v0.9.4 Bump the version to 0.9.4 and add the v0.9.4 fixes to SECURITY.md.
v0.9.3: security release Closes five coordinated-disclosure advisories in the PDF processing path and the Docker Playground UI. GHSA-xpp7-j28w-2gvx arbitrary file write via PDF image-write fields GHSA-q5rj-45vw-vp2g SSRF, PDF fetch followed redirects unvalidated GHSA-v2rm-hvrj-2x9q DoS, unbounded PDF size and page count GHSA-7g3g-vhm6-79f3 XSS, PDF text unescaped into cleaned_html GHSA-m446-hp3q-qfxp DOM XSS in the playground, API token theft No new features. No breaking changes.
docs: release notes, changelog, README, and security credits for v0.9.3
Merge pull request #2077 from unclecode/release/v0.9.2 release: Crawl4AI v0.9.2
Merge pull request #2061 from unclecode/release/v0.9.1 release: Crawl4AI v0.9.1
v0.9.0 - secure-by-default Docker server (breaking); download path-tr… …aversal, stream SSRF, extra_args RCE fixes
PreviousNext