VYPR
Vendor

Crewai

Products
2
CVEs
5
Across products
5
Status
Private

Products

2

Recent CVEs

5
  • CVE-2026-2287CriMar 30, 2026
    risk 0.64cvss 9.8epss 0.01

    CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.

  • CVE-2026-2286CriMar 30, 2026
    risk 0.64cvss 9.8epss 0.00

    CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.

  • CVE-2026-2275CriMar 30, 2026
    risk 0.62cvss 9.6epss 0.00

    The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling.

  • CVE-2026-2285HigMar 30, 2026
    risk 0.49cvss 7.5epss 0.01

    CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.

  • CVE-2026-62240HigJul 13, 2026
    risk 0.00cvss 7.4epss 0.00

    CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect…