Ad

CVE-2026-2286

CRITICAL CVSS 3.1: 9.8 EPSS 0.05%
Updated Apr 06, 2026
Crewai
Parameter Value
CVSS 9.8 (CRITICAL)
Type CWE-918 (Server-Side Request Forgery (SSRF)), CWE-918: Server-Side Request Forgery (SSRF)
Vendor Crewai
Public PoC No

CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Crewai Crewai
cpe:2.3:a:crewai:crewai:1.0:*:*:*:*:*:*:*