1. Home
  2. Blog
  3. Firecrawl

Firecrawl

1 post tagged with “Firecrawl”

CVE-2026-72904: Firecrawl's JSON Schema Parser Leaks Server Files Through $ref Expansion
cvesecurityvulnerability

CVE-2026-72904: Firecrawl's JSON Schema Parser Leaks Server Files Through $ref Expansion

Firecrawl versions before 2.11.32 let authenticated attackers read arbitrary files and perform SSRF via unsafe JSON schema $ref dereferencing. The extraction pipeline follows file and HTTP references without restriction.

Aug 11, 2026
Read
HOL LogoHOL
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.