CVE-2026-2285
EUVD-2026-1711930.03.2026, 16:16
CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| crewai | crewai | 1.0.0 |
𝑥
= Vulnerable software versions
References