Security researcher Yarden Porat from Cyata discovered four vulnerabilities in the framework that expose it to remote code execution (RCE), server-side request forgery (SSRF), and arbitrary local file reads.
These flaws can be triggered through direct or indirect prompt injection, allowing malicious actors to manipulate AI agents into executing unauthorized actions.
The vulnerabilities are tracked under the following identifiers:
SandboxPython environment when Docker is unreachable, allowing attackers to execute arbitrary C function calls via ctypes.The attack heavily relies on the Code Interpreter Tool being active within a CrewAI deployment. An attacker first uses prompt injection to hijack an AI agent.
From there, the impact depends on the host configuration.
On a Docker-enabled host, the attacker can achieve a sandbox escape. On hosts running in configuration or unsafe modes, the attacker can achieve full remote code execution, effectively taking complete control of the device.
Credential theft and lateral network movement are additional post-exploitation risks.
As of now, no complete patch exists for all four vulnerabilities.
The vendor has acknowledged the issues and plans to release updates that block unsafe modules ctypes and enforce fail-secure behavior instead of falling back to an open sandbox.
Until an official fix is released, administrators should take the following steps immediately:
allow_code_execution=True to go off unless absolutely required.Security teams running CrewAI in production environments should treat these vulnerabilities as critical-severity and apply mitigations without delay while awaiting vendor patches.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google
The post CrewAI Vulnerabilities Allow Attackers to Bypass Sandboxes and Compromise Systems appeared first on Cyber Security News.
DETROIT — An urgent investigation is underway in Detroit after multiple students were hospitalized this…
LANSING, Mich. — A major budget standoff is now underway in Michigan after state Senate…
STARKE COUNTY, IND. (WOWO) A former employee of the Starke County Sheriff’s Department has pleaded…
The status of New Hampshire’s end to mandatory car inspections might still be murky in…
Five major dairy farms populated the half-mile stretch of Upper City Road in Pittsfield where…
Resident Evil Requiem players were sad to see the Merchant left out of Leon's latest…
This website uses cookies.