CVE-2026-2285 identifies an arbitrary local file read vulnerability within the CrewAI JSON loader tool, enabling unauthorized access to server files due to insufficient path validation. This remotely exploitable flaw carries a CVSS score of 7.5 High, indicating a significant confidentiality impact without requiring user interaction or complex attack conditions. Currently, there is no evidence of active exploitation or public exploit code, and community attention remains low, as reflected by its very low EPSS score.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:crewai:crewai:1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.