CVE-2026-2286
CRITICALCVSS 9.8/10EPSS 0.47%
Last modified
CVE-2026-2286 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Crewai | Crewai | 1.0.0 |
References
- https://www.kb.cert.org/vuls/id/221883Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-2286?
CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.
How severe is CVE-2026-2286?
CVE-2026-2286 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.47% probability of exploitation in the next 30 days.
How do I fix CVE-2026-2286?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-22854FreeRDP is a free implementation of the Remote Desktop Proto…9.8
- CVE-2026-22855FreeRDP is a free implementation of the Remote Desktop Proto…9.1
- CVE-2026-22856FreeRDP is a free implementation of the Remote Desktop Proto…8.1
- CVE-2026-22857FreeRDP is a free implementation of the Remote Desktop Proto…9.8
- CVE-2026-22858FreeRDP is a free implementation of the Remote Desktop Proto…9.1
- CVE-2026-22859FreeRDP is a free implementation of the Remote Desktop Proto…9.1
- CVE-2026-22860Rack is a modular Ruby web server interface. Prior to versio…7.5
- CVE-2026-22861iccDEV provides a set of libraries and tools that allow for …8.8
- CVE-2026-22862go-ethereum (geth) is a golang execution layer implementatio…7.5
- CVE-2026-22863Deno is a JavaScript, TypeScript, and WebAssembly runtime. B…7.5
- CVE-2026-22864Deno is a JavaScript, TypeScript, and WebAssembly runtime. B…9.8
- CVE-2026-22865Gradle is a build automation tool, and its native-platform t…7.4
Are you affected by CVE-2026-2286?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
