Multiple Vulnerabilities in CrewAI Enable RCE and SSRF Attacks

Multiple Vulnerabilities in CrewAI Enable RCE and SSRF Attacks

First seen 2 Apr 2026, 11:32 UTC Kb.CertReddit 77% similarity 67.5

Article Content

Browse articles
ThreatCluster

Four critical vulnerabilities have been discovered in CrewAI, a Python multi-agent framework, including CVE-2026-2275, CVE-2026-2286, CVE-2026-2287, and CVE-2026-2285. These vulnerabilities allow attackers to exploit the Code Interpreter Tool through prompt injection, leading to remote code execution (RCE), arbitrary local file read, and server-side request forgery (SSRF). The vulnerabilities stem from improper configurations and fallback behaviors when Docker is not available. Currently, there is no full patch released, and the CrewAI maintainers are working on mitigations. The attack vector requires only access to the CrewAI agent with the Code Interpreter Tool enabled, making it a significant risk for deployments. The vulnerabilities were published on 2026-03-30, and the situation remains critical as no CVSS scores have been assigned yet.

Key Points: • Four CVEs in CrewAI allow for RCE and SSRF via prompt injection. • Attackers need access to the CrewAI agent with the Code Interpreter Tool enabled. • No full patch is available; mitigations are in progress.

ThreatCluster AI

Timeline

2026-03-30
CVE-2026-2275, CVE-2026-2286, CVE-2026-2287, CVE-2026-2285 published
2026-04-02
Researcher discloses vulnerability chain and current status

Community

Browse all →