VYPR
Critical severity9.8NVD Advisory· Published Mar 30, 2026· Updated Jun 17, 2026

CVE-2026-2286

CVE-2026-2286

Description

CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Crewai/Crewai2 versions
    cpe:2.3:a:crewai:crewai:1.0.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:crewai:crewai:1.0.0:*:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.