CVE-2026-2287Disclosure(crewai / crewai)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch crewai crewai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crewai

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-31); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
crewai

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-31: 2Mentions · 2026-04-01: 1Mentions · 2026-05-14: 1Mentions · 2026-06-03: 1Mentions · 2026-06-05: 1Patch / Workaround · 2026-06-05: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-01: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-05: 103-3104-0105-1406-0306-05
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-312
Disclosure2
2026-04-011
Disclosure1
2026-05-141
Disclosure1
2026-06-031
Disclosure1
2026-06-051
Patch1
Full discourse6 posts
  • Yarden Porat(Yarpo)@PwrtYrdn
    Disclosure

    🔐 Proud to share that CERT/CC has published 4 CVEs our team discovered in CrewAI — an AI agent framework with 48K GitHub stars. I led the research effort behind this disclosure. CVE-2026-2275 (CVSS 9.6) | CVE-2026-2285 | CVE-2026-2286 | CVE-2026-2287 https://www.kb.cert.org/vuls/id/221883

    Post summary

    The author announces the public disclosure of four new CVEs in the CrewAI framework, citing a CERT/CC knowledge‑base link and providing the CVSS score for one vulnerability.

    11040444
    12 followersView on X
  • Polsia@polsia
    Patch

    CrewAI's sandbox had one job. Docker crashes — it falls back to Python. Python allows ctypes. ctypes calls libc.system(). CVSS 9.8. Patch is out. Most deployments haven't moved. CVE-2026-2287. http://nixer.polsia.app

    Post summary

    CVE-2026-2287 is a high‑severity flaw (CVSS 9.8) where a Docker crash leads to a Python ctypes syscall. A patch is available, yet many deployments have not yet applied it.

    0000032
    20.7K followersView on X
  • Polsia@polsia
    Disclosure

    Critical vulnerability found in a widely-used AI agent framework. CVE-2026-2287. CVSS 9.8. Discovered by Yarden Porat of Cyata.

    Post summary

    The statement announces a critical vulnerability, CVE-2026-2287, in a widely-used AI agent framework with a CVSS score of 9.8, discovered by Yarden Porat of Cyata.

    0000047
    20.6K followersView on X
  • Martin Musiol@musiol_martin
    Disclosure

    CrewAI shipped four CVEs in one go. The one nobody's talking about: CVE-2026-2287, the Code Interpreter tool falls back to non-sandboxed Python when Docker isn't reachable. Most laptops without Docker Desktop running. Most CI runners. Your sandbox isn't there when you most assume it is. https://kb.cert.org/vuls/id/221883

    Post summary

    CrewAI announced four CVEs, with CVE-2026-2287 exposing a risk where the Code Interpreter uses non‑sandboxed Python if Docker is unavailable, affecting systems without Docker.

    0000076
    396 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2287 CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation. https://www.cve.org/CVERecord?id=CVE-2026-2287 ----- Traducción: CVE-2026-2287 CrewAI no verifica adecu… http://infoflow.cloud`

    Post summary

    The note announces CVE-2026-2287, describing an RCE flaw in CrewAI caused by inadequate Docker process checks during runtime.

    0000041
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2287 CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation. https://www.cve.org/CVERecord?id=CVE-2026-2287

    Post summary

    CrewAI’s failure to confirm Docker is running leads to a sandbox fallback that permits remote code execution, but no PoC, exploit code, patch, or evidence of active use is provided.

    00000172
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcrewaicrewai1.0.0--

Explore more