Description
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying in any import statements. In other words, a within-process sandbox cannot merely account for the import system and instead must account for the complete runtime of the Python interpreter.
Published: 2026-09-13
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox Escape Leading to Code Execution
Action: Patch Now
AI Analysis

Impact

CrewAI implements a Python blocklist mechanism that only intercepts import statements, leaving other runtime features of the interpreter unrestricted. Because of this design flaw, an attacker can invoke functions such as ctypes.CDLL(None) to load and execute arbitrary C libraries without triggering the blocklist. This allows the attacker to bypass the intended sandbox, gain execution privileges within the process, and potentially compromise confidentiality, integrity, and availability of the host system.

Affected Systems

All CrewAI releases before the commit identified as fb2323b3deb3ec62b3965526857e77a2264e4cd0 are affected. Users of versions that were released without incorporating this patch remain vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.1. The EPSS score is less than 1%, suggesting a very low probability that the flaw will be actively exploited. The item is not listed in the CISA KEV catalog. The attack vector is a within‑process sandbox escape that requires the attacker to execute code in the sandboxed environment but does not need external network access. Once reached, the attacker can load arbitrary libraries and execute code potentially catastrophic if the sandbox is used to run untrusted code.

Generated by OpenCVE AI on September 15, 2026 at 18:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CrewAI to the patched version (commit fb2323b3deb3ec62b3965526857e77a2264e4cd0) or any newer release that addresses this issue.
  • If an immediate patch is unavailable, remove or disable access to the ctypes module in the sandboxed environment to prevent use of ctypes.CDLL and related calls.
  • Implement additional runtime restrictions so that calls to external C libraries or privileged system functions are blocked or strictly filtered, ensuring the sandbox cannot rely solely on import‑time checks.

Generated by OpenCVE AI on September 15, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via ctypes.CDLL in CrewAI

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title CrewAI Sandbox Escape via Improper Blocking of Python Module Imports
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title CrewAI Sandbox Escape via Improper Blocking of Python Module Imports

Sun, 13 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying in any import statements. In other words, a within-process sandbox cannot merely account for the import system and instead must account for the complete runtime of the Python interpreter.
First Time appeared Crewai
Crewai crewai
Weaknesses CWE-424
CPEs cpe:2.3:a:crewai:crewai:*:*:*:*:*:*:*:*
Vendors & Products Crewai
Crewai crewai
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:37:55.095Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-37008

cve-icon Vulnrichment

Updated: 2026-09-14T16:37:33.493Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T21:17:01.303

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-37008

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses
  • CWE-424

    Improper Protection of Alternate Path