Firecrawl Playwright Service Server-Side Request Forgery Protection Bypass Vulnerability

Vulnerability

A server-side request forgery (SSRF) protection bypass vulnerability has been identified in Firecrawl versions through 2.8.0, specifically within the Playwright scraping service. This vulnerability arises because network policy validation is only applied to the initial user-supplied URL, allowing attackers to exploit HTTP redirects to access internal or restricted resources. By sending a valid external URL that redirects to a sensitive endpoint, the browser can fetch the final destination without revalidation, potentially exposing internal network services. This issue is distinct from general redirect-based SSRF vulnerabilities, as it specifically involves a gap in post-redirect validation of SSRF protections.

Impact

Exploitation of this vulnerability allows unauthorized access to internal network services and sensitive endpoints by bypassing SSRF protections through manipulated HTTP redirects.

Remediation

Users of the open-source version of Firecrawl should update to version 1.1.1 and supply the Playwright services with a secure proxy that blocks traffic to link-local IP addresses. For those using the hosted version, no action is needed as the vulnerability has already been patched.

Added: Mar 26, 2026, 6:29 PM
Updated: Mar 26, 2026, 6:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.8
remediation
0.0
relevance
4.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.