{"id":"CVE-2025-28197","aliases":["PYSEC-2026-1281"],"url":"https://o3.security/vulnerability/CVE-2025-28197","summary":"Crawl4AI SSRF vulnerability","details":"Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.","published":"2025-04-18T21:31:20Z","modified":"2026-07-07T17:57:04.208001337Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"crawl4ai","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-28197"},{"type":"WEB","url":"https://gist.github.com/AndrewDzzz/f49e79b09ce0643ee1fc2a829e8875e0"},{"type":"PACKAGE","url":"https://github.com/unclecode/crawl4ai"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:57:04.208001337Z"}}