Vulnerability Bulletins |
CVE-2026-91942 |
|
| Affected software | DOCKER |
| crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-91942 | |






