Known Vulnerabilities for CrewAI by CrewAIInc
Listed below are 4 of the newest known vulnerabilities associated with "CrewAI" by "CrewAIInc".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-62240 json | CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot... | Not Provided | 2026-07-13 | 2026-07-14 |
| CVE-2026-37009 json | A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL comm... | Not Provided | 2026-08-27 | 2026-08-31 |
| CVE-2026-37008 json | CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnera... | Not Provided | 2026-09-13 | 2026-09-13 |
| CVE-2026-37007 json | A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicio... | Not Provided | 2026-08-27 | 2026-09-01 |