Known Vulnerabilities for products from Crewai
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Crewai".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-62240 json | CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot... | Not Provided | 2026-07-13 | 2026-07-14 |
| CVE-2026-2287 json | CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allo... | Not Provided | 2026-03-30 | 2026-04-06 |
| CVE-2026-2286 json | CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services... | Not Provided | 2026-03-30 | 2026-04-06 |
| CVE-2026-2285 json | CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, e... | Not Provided | 2026-03-30 | 2026-04-06 |