Product
crewai
3 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-2287
CVE-2026-2286
CVE-2026-2285
all versions
CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows fo
all versions
CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, fac
all versions
CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabli