What is CVE-2026-72904?
CVE-2026-72904 is a critical arbitrary file read vulnerability in Firecrawl versions prior to 2.11.32, caused by unsafe dereferencing of user-supplied JSON schemas in the extraction functionality. Organizations should immediately update to the latest version to mitigate the risk.
Azərbaycanca: CVE-2026-72904 Firecrawl-un 2.11.32 versiyasından əvvəlki versiyalarında kritik bir zəiflikdir. İstifadəçi tərəfindən təqdim olunan JSON sxemlərinin təhlükəsiz olmayan şəkildə dereferencing edilməsi ilə bağlıdır və ixtiyari fayl oxumağa imkan verir. Təşkilatlar dərhal Firecrawl-u ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of Firecrawl are affected by CVE-2026-72904?
This vulnerability affects all versions of Firecrawl prior to version 2.11.32.
What should organizations do to mitigate CVE-2026-72904?
Organizations should immediately update Firecrawl to the latest version to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.