ended5월 15일· 1 sources
Critical SSRF Vulnerabilities Discovered in Widely-Used Crawlee Web Scraping Library
인기 웹 스크래핑 라이브러리 Crawlee의 SSRF 취약점 발견
Why it matters
Crawlee is deployed across personal projects and multi-tenant SaaS platforms monitoring hundreds of customer websites, making these SSRF vulnerabilities exceptionally dangerous. The root cause—lack of URL validation outside a single function—enables attackers to bypass security controls and exfiltrate sensitive data through multiple attack vectors. This research exposes critical blind spots in how the library sanitizes URLs before passing them to HTTP clients.
1
Sources
+0
24h
—
Growth
6d
Active
CrawleeSSRF vulnerabilityData exfiltrationWeb scraperURL validation