CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.kb.cert.org/vuls/id/221883 |
|
History
Mon, 30 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server. | |
| Title | CVE-2026-2285 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-03-30T15:51:39.962Z
Reserved: 2026-02-10T14:41:48.845Z
Link: CVE-2026-2285
No data.
Status : Received
Published: 2026-03-30T16:16:04.670
Modified: 2026-03-30T16:16:04.670
Link: CVE-2026-2285
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.