CVE-2026-2286
EUVD-2026-1712130.03.2026, 16:16
CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| crewai | crewai | 1.0.0 |
𝑥
= Vulnerable software versions
References