PT-2025-34801 · Firecrawl · Firecrawl

·

CVE-2025-57818

·

Published

2025-08-26

·

Updated

2025-08-26

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Firecrawl versions prior to 2.0.1
Description: Firecrawl is a tool that converts websites into LLM-ready markdown or structured data. A server-side request forgery (SSRF) vulnerability exists in the webhook functionality of Firecrawl. Authenticated users could configure a webhook to an internal URL and send POST requests with arbitrary headers, potentially allowing access to internal systems.
Recommendations: Upgrade to version 2.0.1 or later. If upgrading is not possible, isolate Firecrawl from any sensitive internal systems.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-57818
GHSA-P2WG-PRHF-JX79

Affected Products

Firecrawl