CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS rebinding techniques to access internal services and cloud metadata endpoints.
References
| Link | Resource |
|---|---|
| https://github.com/crewAIInc/crewAI/commit/5d4851eac797cafc45b726f65747fe2c9520fc42 | Patch |
| https://github.com/crewAIInc/crewAI/issues/6520 | Issue Tracking Exploit Patch |
| https://github.com/crewAIInc/crewAI/pull/6331 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/crewAIInc/crewAI/releases/tag/1.15.1 | Release Notes |
| https://www.vulncheck.com/advisories/crewai-ssrf-filter-bypass-via-http-redirect-in-scrape-tools | Third Party Advisory VDB Entry |
Configurations
History
14 Jul 2026, 18:52
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Crewai
Crewai crewai |
|
| CPE | cpe:2.3:a:crewai:crewai:*:*:*:*:*:*:*:* | |
| References | () https://github.com/crewAIInc/crewAI/commit/5d4851eac797cafc45b726f65747fe2c9520fc42 - Patch | |
| References | () https://github.com/crewAIInc/crewAI/issues/6520 - Issue Tracking, Exploit, Patch | |
| References | () https://github.com/crewAIInc/crewAI/pull/6331 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://github.com/crewAIInc/crewAI/releases/tag/1.15.1 - Release Notes | |
| References | () https://www.vulncheck.com/advisories/crewai-ssrf-filter-bypass-via-http-redirect-in-scrape-tools - Third Party Advisory, VDB Entry |
13 Jul 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-13 22:16
Updated : 2026-07-14 18:52
NVD link : CVE-2026-62240
Mitre link : CVE-2026-62240
CVE.ORG link : CVE-2026-62240
JSON object : View
Products Affected
crewai
- crewai
CWE
CWE-918
Server-Side Request Forgery (SSRF)
