cvesecurityvulnerability
CVE-2026-72904: Firecrawl's JSON Schema Parser Leaks Server Files Through $ref Expansion
Firecrawl versions before 2.11.32 let authenticated attackers read arbitrary files and perform SSRF via unsafe JSON schema $ref dereferencing. The extraction pipeline follows file and HTTP references without restriction.