Vulnerabilities
Vulnerable Software
Crewai:  >> Crewai  Security Vulnerabilities
CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.
CVSS Score
7.5
EPSS Score
0.001
Published
2026-03-30
CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.
CVSS Score
9.8
EPSS Score
0.001
Published
2026-03-30
CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.
CVSS Score
9.8
EPSS Score
0.001
Published
2026-03-30


Contact Us

Shodan ® - All rights reserved