PT-2026-29050 · Crewai · Crewai

Yarden Porat

·

Publicado

2026-03-30

·

Atualizado

2026-04-02

·

CVE-2026-2286

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CrewAI (affected versions not specified)
Description CrewAI contains a server-side request forgery condition that allows for the acquisition of content from internal and cloud services. This is facilitated by Retrieval-Augmented Generation (RAG) search tools that do not properly validate URLs provided during runtime. The issue allows an attacker to potentially access resources that should not be publicly accessible.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2286

Produtos afetados

Crewai