Filtered by vendor Crewai
Subscribe
Total
4 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-62240 | 1 Crewai | 1 Crewai | 2026-07-14 | N/A | 7.4 HIGH |
| CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS rebinding techniques to access internal services and cloud metadata endpoints. | |||||
| CVE-2026-2287 | 1 Crewai | 1 Crewai | 2026-06-17 | N/A | 9.8 CRITICAL |
| CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation. | |||||
| CVE-2026-2286 | 1 Crewai | 1 Crewai | 2026-06-17 | N/A | 9.8 CRITICAL |
| CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime. | |||||
| CVE-2026-2285 | 1 Crewai | 1 Crewai | 2026-06-17 | N/A | 7.5 HIGH |
| CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server. | |||||
