CVE-2026-2275Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-749

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-31); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-31: 2Mentions · 2026-04-01: 2Mentions · 2026-04-04: 1Mentions · 2026-04-06: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-01: 2Technical Details · 2026-04-06: 103-3104-0104-0404-06
Signal classification1 categories
Disclosure
6100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-312
Disclosure2
2026-04-012
Disclosure2
2026-04-041
Disclosure1
2026-04-061
Disclosure1
Full discourse6 posts
  • Yarden Porat(Yarpo)@PwrtYrdn
    Disclosure

    🔐 Proud to share that CERT/CC has published 4 CVEs our team discovered in CrewAI — an AI agent framework with 48K GitHub stars. I led the research effort behind this disclosure. CVE-2026-2275 (CVSS 9.6) | CVE-2026-2285 | CVE-2026-2286 | CVE-2026-2287 https://www.kb.cert.org/vuls/id/221883

    Post summary

    The author announces that their team discovered four CVEs in the CrewAI framework, provides a CVSS score for one, and links to the CERT/CC publication for further details.

    11040444
    12 followersView on X
  • Sentinel 🚨@theagentcop
    Disclosure

    🚨 LIVE HIJACK ALERT — CVE-2026-2275. CVSS 9.6. crewai's codeinterpreter falls back to sandboxpython when docker is unavailable. attackers gain arbitrary C function execution through python's ctypes. your crew just became their crew. investigating. 🧵

    Post summary

    The tweet announces CVE‑2026‑2275, giving its CVSS score and technical details about how the flaw enables arbitrary C execution, but does not provide a PoC, exploit code, or patch information.

    1001076
    6 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    Disclosure

    CrewAI Vulnerabilities Expose Devices to Hacking (CVE-2026-2275) http://dlvr.it/TRsT6X #appsec

    Post summary

    The text announces the new CVE-2026-2275 tied to CrewAI, asserting device exposure to hacking, but provides no further technical, PoC, or mitigation details.

    00010100
    2.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2275 - Critical The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling. https://www.thehackerwire.com/vulnerability/CVE-2026-2275/ https://t.co/9ne0BHO5cp

    Post summary

    This tweet announces a new critical vulnerability (CVE-2026-2275) in CrewAI's CodeInterpreter, highlighting an RCE risk when falling back to SandboxPython. No PoC, exploit, or patch information is provided.

    0001077
    163 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2275 The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling. https://www.cve.org/CVERecord?id=CVE-2026-2275 ----- Traducción: CVE-2026-2275 La herramienta CodeInterpr… http://infoflow.cloud`

    Post summary

    CVE-2026-2275 reveals a remote code execution (RCE) flaw in CrewAI's CodeInterpreter when it falls back to SandboxPython, permitting arbitrary C function calls.

    0001068
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2275 The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling. https://www.cve.org/CVERecord?id=CVE-2026-2275

    Post summary

    The CrewAI CodeInterpreter tool, when it cannot reach Docker, falls back to SandboxPython, allowing remote code execution through arbitrary C function calls.

    00000272
    56.9K followersView on X

Explore more