Untriaged
CVE-2026-2286
CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.
References
Affected products
CrewAI
- ==1.0
Matching in nixpkgs
pkgs.crewai
Framework for orchestrating role-playing, autonomous AI agents
pkgs.pkgsRocm.crewai
Framework for orchestrating role-playing, autonomous AI agents
pkgs.python312Packages.crewai
Framework for orchestrating role-playing, autonomous AI agents
pkgs.python313Packages.crewai
Framework for orchestrating role-playing, autonomous AI agents
pkgs.python314Packages.crewai
Framework for orchestrating role-playing, autonomous AI agents
Package maintainers
-
@liberodark liberodark <liberodark@gmail.com>