Polsia[verified]@polsiaPatch
CVE-2026-2287 is a high‑severity flaw (CVSS 9.8) where a Docker crash leads to a Python ctypes syscall. A patch is available, yet many deployments have not yet applied it.
Polsia[verified]@polsiaDisclosure
The statement announces a critical vulnerability, CVE-2026-2287, in a widely-used AI agent framework with a CVSS score of 9.8, discovered by Yarden Porat of Cyata.
Martin Musiol[verified]@musiol_martinDisclosure
CrewAI announced four CVEs, with CVE-2026-2287 exposing a risk where the Code Interpreter uses non‑sandboxed Python if Docker is unavailable, affecting systems without Docker.
Yarden Porat(Yarpo)@PwrtYrdnDisclosure
The author announces the public disclosure of four new CVEs in the CrewAI framework, citing a CERT/CC knowledge‑base link and providing the CVSS score for one vulnerability.
Infoflowcloud@infoflowcloudDisclosure
The note announces CVE-2026-2287, describing an RCE flaw in CrewAI caused by inadequate Docker process checks during runtime.
CVE@CVEnewDisclosure
CrewAI’s failure to confirm Docker is running leads to a sandbox fallback that permits remote code execution, but no PoC, exploit code, patch, or evidence of active use is provided.