← Back

Crewai

crewai

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Crewai
crewai

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Crewai
1Crewai
Apr 15, 2026
Mar 30, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.
1Crewai
1Crewai
Apr 15, 2026
Mar 30, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.
1Crewai
1Crewai
Apr 15, 2026
Mar 30, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.