ZDI-CAN-28387: ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability
Published Sep 16, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must load a malicious agent configuration from the repository. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92206.
Affected Software
2 affected components
crewai/crewAI
CrewAI CrewAI
Event History
Sep 16, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What must an attacker convince a target to do to exploit this issue?
The target must load a malicious agent configuration from a repository. Exploitation requires this user interaction before arbitrary code execution can occur.
2
What is the potential impact after successful exploitation?
A remote attacker can execute arbitrary code on the affected CrewAI crewAI installation.
3
How severe is this vulnerability?
ZDI assigned it a CVSS score of 8.8. It is tracked as CVE-2026-92206.