Vulnerability Description
CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Crewai | Crewai | 1.0.0 |
Related Weaknesses (CWE)
References
- https://www.kb.cert.org/vuls/id/221883Third Party AdvisoryVDB Entry
FAQ
What is CVE-2026-2287?
CVE-2026-2287 is a vulnerability with a CVSS score of 9.8 (CRITICAL). CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.
How severe is CVE-2026-2287?
CVE-2026-2287 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-2287?
Check the references section above for vendor advisories and patch information. Affected products include: Crewai Crewai.