CVE-2026-2285: Path Traversal
Published Mar 30, 2026
·Updated
CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.
Affected Software
2 affected components
CrewAI CrewAI
CrewAI CrewAI=1.0.0
Event History
Mar 30, 2026
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-2285?
CVE-2026-2285 is considered a high severity vulnerability due to the potential for unauthorized access to sensitive files.
2
How do I fix CVE-2026-2285?
To fix CVE-2026-2285, update the CrewAI software to the latest version that addresses the local file read vulnerability.
3
What types of files can be accessed through CVE-2026-2285?
CVE-2026-2285 allows access to any file on the server that is readable by the user running the CrewAI application.
4
Is CVE-2026-2285 a remote or local vulnerability?
CVE-2026-2285 is a local vulnerability since it requires access to the server running CrewAI.
5
What impact does CVE-2026-2285 have on data security?
CVE-2026-2285 can lead to unauthorized data exposure, potentially compromising sensitive information stored on the server.