SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-62240

HIGH · CVSS 7.4 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

CrewAI versions prior to 1.15.1 are vulnerable to a server-side request forgery (SSRF) flaw in the validate_url function, allowing attackers to manipulate URL inputs to access internal services or cloud metadata endpoints. This could lead to unauthorized data exposure or further exploitation of internal network resources. Organizations using CrewAI should prioritize patching to mitigate the risk of this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-62240
Severity
HIGH
CVSS
7.4
EPSS
0.31%

Original NVD Description

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS rebinding techniques to access internal services and cloud metadata endpoints.

Related CVEs

Other vulnerabilities affecting the same vendor(s)