logo

CrewAI Hit by Critical Vulnerabilities Enabling Sandbox Escape and Host Compromise

ID: 6ef15821-48de-5972-85b8-0be29de9f457

STIX ID: report--6ef15821-48de-5972-85b8-0be29de9f457

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: Divya

...
...

CrewAI is reported to contain four critical vulnerabilities in its Code Interpreter and related tools that permit remote code execution, SSRF, and arbitrary local file reads by exploiting insecure fallback behaviors (e.g., fallback to a SandboxPython environment when Docker is unavailable) and improper input validation. The vendor has acknowledged the issues and plans mitigations; administrators are advised to disable the Code Interpreter, set allow_code_execution=False, sanitize untrusted inputs, and monitor Docker availability until patches are released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.