Crewai is an AI agent framework and automation platform where identified vulnerabilities center on code-injection risks and server-side request forgery, reflecting the security surface of dynamically generated agent workflows and external API integration. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Crewai over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-62240HIGH CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning t | Jul 13, 2026 | 7.4 | 33 | NO | NO |
CVE-2026-2287CRITICAL CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation. | Mar 30, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-2286CRITICAL CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly vali | Mar 30, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-2285HIGH CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server. | Mar 30, 2026 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Crewai.
Media articles that mention a CVE ID that affects a product developed by Crewai — matched by CVE ID, not by vendor name.