logo

Critical CrewAI Vulnerabilities Allow RCE and Sandbox Escapes via Prompt Injection

ID: bbabe267-2d97-5c71-b772-91f069fc51be

STIX ID: report--bbabe267-2d97-5c71-b772-91f069fc51be

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-04-23

Author: Ddos

...
...

A CERT/CC note details multiple vulnerabilities in the CrewAI framework (including CVE-2026-2275, CVE-2026-2287, CVE-2026-2286, CVE-2026-2285) that allow SSRF, local file reads, and remote code execution by exploiting insecure fallback behaviors in the Code Interpreter Tool and sandboxing; attackers can chain these via prompt injection to steal credentials or achieve full RCE, and while the vendor plans mitigations some issues remain unpatched — operators should disable code execution tools when possible, sanitize inputs, and ensure Docker availability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.