[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":44,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":51,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":57,"vulnerability-29613":64},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",["Island",45],{"key":46,"params":47,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":48},"{}",{"head":50},{},["Island",52],{"key":53,"params":54,"result":55},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":48},{"head":56},{},["Island",58],{"key":59,"params":60,"result":62},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":61},"{\"text-color\":\"gray\"}",{"head":63},{},{"id":65,"detectable_with":66,"vuln_details":73,"vuln_id":92,"name":93,"published":94,"updated":74},29613,{"tool":67,"engine":70},{"id":68,"name":69},1,"Network Scanner",{"id":71,"name":72},2,"Nuclei",{"id":65,"codename":74,"description":74,"severity":75,"risk_description":76,"public_description":77,"public_recommendation":78,"recommendation":74,"references":79,"cvssv3":84,"epss_score":85,"epss_percentile":86,"cve":87,"in_cisa_catalog":9,"date":89,"software_type":74,"vendor":90,"product":91,"ptt_exploit_capabilities":74},null,"critical","Unauthenticated attackers can forge valid JWT authentication tokens and gain full access to protected Crawl4AI API endpoints (crawling, screenshot, PDF generation, JavaScript execution, and library context retrieval), resulting in complete compromise of the deployment's intended access control.","Crawl4AI Docker API server versions before 0.8.7 ship with a hardcoded default JWT signing key (\"mysecret\") used to sign and verify HS256 authentication tokens. Because the key is identical across every deployment where SECRET_KEY has not been overridden, an unauthenticated attacker can forge a valid Bearer token and use it to access every JWT-protected API endpoint (\u002Fmd, \u002Fhtml, \u002Fscreenshot, \u002Fpdf, \u002Fexecute_js, \u002Fcrawl, \u002Fask).","Upgrade Crawl4AI to version 0.8.7 or later, which removes the hardcoded default signing key, rejects known weak secrets, and auto-generates an ephemeral key when JWT authentication is enabled without an explicit SECRET_KEY. As a workaround, set the SECRET_KEY environment variable to a strong random value.",[80,81,82,83],"https:\u002F\u002Fgithub.com\u002Funclecode\u002Fcrawl4ai\u002Fsecurity\u002Fadvisories\u002FGHSA-365w-hqf6-vxfg","https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fcrawl4ai-authentication-bypass-via-hardcoded-jwt-signing-key","https:\u002F\u002Fgithub.com\u002Funclecode\u002Fcrawl4ai","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-56265",9.8,0.02639,0.84841,[88],"CVE-2026-56265","2026-06-21T00:00:00Z","unclecode","crawl4ai","NETSCAN-NUCLEI-CVE-CVE-2026-56265","Crawl4AI \u003C 0.8.7 - Hardcoded JWT Signing Key Authentication Bypass","2026-08-19T00:00:00Z"]