CVE-2026-62240EPSS p42.2%

CVE-2026-62240CVE-2026-62240

crewai / crewai

Description

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS rebinding techniques to access internal services and cloud metadata endpoints.

Scoring

CVSS 7.4 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
EPSS0.52% probability of exploitation · percentile 42.2% · 2026-10-05T12:00:23Z
Last modified2026-09-17
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.