PT-2025-34801 · Firecrawl · Firecrawl
Amplitudesxd
·
Published
2025-08-26
·
Updated
2025-08-26
·
CVE-2025-57818
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Firecrawl versions prior to 2.0.1
Description:
Firecrawl is a tool that converts websites into LLM-ready markdown or structured data. A server-side request forgery (SSRF) vulnerability exists in the webhook functionality of Firecrawl. Authenticated users could configure a webhook to an internal URL and send POST requests with arbitrary headers, potentially allowing access to internal systems.
Recommendations:
Upgrade to version 2.0.1 or later.
If upgrading is not possible, isolate Firecrawl from any sensitive internal systems.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firecrawl