CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.
References
| Link | Resource |
|---|---|
| https://www.kb.cert.org/vuls/id/221883 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2026-03-30 16:16
Updated : 2026-06-17 10:30
NVD link : CVE-2026-2287
Mitre link : CVE-2026-2287
CVE.ORG link : CVE-2026-2287
JSON object : View
Products Affected
crewai
- crewai
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
