Impact
CrewAI implements a Python blocklist mechanism that only intercepts import statements, leaving other runtime features of the interpreter unrestricted. Because of this design flaw, an attacker can invoke functions such as ctypes.CDLL(None) to load and execute arbitrary C libraries without triggering the blocklist. This allows the attacker to bypass the intended sandbox, gain execution privileges within the process, and potentially compromise confidentiality, integrity, and availability of the host system.
Affected Systems
All CrewAI releases before the commit identified as fb2323b3deb3ec62b3965526857e77a2264e4cd0 are affected. Users of versions that were released without incorporating this patch remain vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1. The EPSS score is less than 1%, suggesting a very low probability that the flaw will be actively exploited. The item is not listed in the CISA KEV catalog. The attack vector is a within‑process sandbox escape that requires the attacker to execute code in the sandboxed environment but does not need external network access. Once reached, the attacker can load arbitrary libraries and execute code potentially catastrophic if the sandbox is used to run untrusted code.
OpenCVE Enrichment