Back to list

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args — GHSA-R253-R9JW-QG44

GitHub · GitHub · GHSA-R253-R9JW-QG44

ID
GHSA-R253-R9JW-QG44
Date
Activity
Source
GitHub
Vendor
GitHub
Threat
critical
CVSS
10

Summary

### Summary The Docker API server accepted a request-supplied `browser_config.extra_args`, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command (`--utility-cmd-prefix`, `--renderer-cmd-prefix`, `--gpu-launcher`, `--browser-subprocess-path`) together with `--no-zygote`, causing Chromium to fork/exec an attacker-controlled command as the…

Product

pip: crawl4ai

What to do

General, cautious steps (verify details in the official source):

  • Prioritize patching or mitigation immediately (treat as actively risky).
  • Identify affected product versions in your inventory and verify whether you are impacted.
  • Apply vendor patches/updates or recommended mitigations as soon as available.
  • Read the official advisory for exact affected versions and remediation steps.

Official advisory

Related advisories