CVE-2026-37007

Published: Ago 27, 2026 Last Modified: Ago 27, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument.

https://github.com/crewAIInc/crewAI/commit/713fa7d
https://yerangamage.com/cves/detail/?slug=crewai-file-write