CVE-2026-37007

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-22: 109-22
Referenced assets1 URL
By indicator
Full discourse1 post
  • Dipen Vaja@dipenvaja

    CrewAI's FileWriterTool path traversal (CVE-2026-37007) is the multi-agent filesystem scare of the week. Untrusted filenames, arbitrary writes, update past the vulnerable crewai-tools line and stop letting agents name files like they're trusted coworkers. Same scroll: Steam Frame coverage keeps landing on OpenXR eye tracking and foveated rendering as the real platform shift. Second standalone target for VR builders, SteamOS underneath, eye tracking in the OpenXR path. Agents that write files need a blast radius. Headsets that track eyes need a privacy story. When the claim is "we verified this build / this drop / this entitlement," http://craterclaim.com is the receipt rail I keep bookmarking. Patch your tools. Ship your OpenXR path. Don't confuse a demo with a control.

    10000162
    84 followersView on X

Explore more