CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.
Loading...
Loading...
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2026-03-30. NVD baseline CVSS 9.8; sources differ by 0.0.
CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.
March 30, 2026
April 15, 2026
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-2286
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.