CVE-2026-2287: Code Injection
Published Mar 30, 2026
·Updated
CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.
Affected Software
2 affected components
CrewAI CrewAI
CrewAI CrewAI=1.0.0
Event History
Mar 30, 2026
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software