Security Advisory

CVE-2026-2286

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-30 15:51:25
Last updated 2026-04-01 18:46:31
Assigner certcc
State PUBLISHED

Description

CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.