Ad

CVE-2026-2285

HIGH CVSS 3.1: 7.5 EPSS 0.17%
Updated Apr 06, 2026
Crewai
Parameter Value
CVSS 7.5 (HIGH)
Type CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vendor Crewai
Public PoC No

CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Crewai Crewai
cpe:2.3:a:crewai:crewai:1.0:*:*:*:*:*:*:*