Repository navigation
[GHSA-365w-hqf6-vxfg] Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution - #10304
Conversation
|
Hi there @unclecode! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
🟡 Changes recommended
The valid CVSS v3 severity entry should be retained as described.
1 open finding
What changed in this PR
Corrects CVSS v4 validation for the Crawl4AI advisory.
Changes:
- Removes the invalid trailing slash from the CVSS v4 vector.
- Updates the modification timestamp.
- Removes the CVSS v3 entry, contrary to the stated scope.
| File | Description |
|---|---|
GHSA-365w-hqf6-vxfg.json |
Updates severity metadata and timestamp. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| { | ||
| "type": "CVSS_V4", | ||
| "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/" | ||
| "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N" |
There was a problem hiding this comment.
The reason CVSS v3 is applied is that if CVSS v4 is present, only CVSS v4 modifications can be made, and CVSS v3 is automatically deleted. It is not intentionally deleted.

Updates
Comments
Fix CVSS v4 validation.