unclecode shipped Crawl4AI v0.9.4 on 2026-09-23 (PyPI crawl4ai 0.9.4). It closes three coordinated advisories: blind SSRF via robots.txt (GHSA-f77g-77vp-r96v), SSRF with response disclosure via link_preview (GHSA-wh5w-hmj3-vgg7, high), and a dict-wrapper trust-boundary bypass that let non-admin clients read server env vars (GHSA-5w5p-vcv6-mm3f, high). A process-wide egress_policy wires the Docker PinningProxy into library HTTP clients. Default pruning switches to lxml-native PruningContentFilterLXML (~10×: 134→13 ms medium page; 2200→260 ms on a 6000-card page). Self-hosted Docker servers should upgrade.
Key Takeaways
- ✓Shipped: v0.9.4 / PyPI 0.9.4; Docker: unclecode/crawl4ai:0.9.4
- ✓Security: three GHSAs closed; robots + link_preview SSRF and env-leak via dict laundering; pinning egress proxy
- ✓Perf: PruningContentFilterLXML default ~10× faster pruning with byte-identical output
- ✓Ops: CRAWL4AI_MAX_TIMEOUT_MS; pool max_pages_before_recycle=200
- ✓Install: docs.crawl4ai.com + pip install crawl4ai==0.9.4
Discussion & Comments
0Sign in to join the discussion
Connect with AI developers to exchange benchmark insights.