1.14.7.dev20260617
2 years ago
2 days ago
Known vulnerabilities in the crewai-tools package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
crewai-tools is a Set of tools for the crewAI framework Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to the RAG search tools not properly validating user-supplied URLs at runtime. An attacker can access internal or cloud resources by supplying crafted URLs. How to fix Server-side Request Forgery (SSRF)? Upgrade | [,1.14.0) |
crewai-tools is a Set of tools for the crewAI framework Affected versions of this package are vulnerable to Arbitrary Code Injection due to improper verification of the Docker runtime status, causing a fallback to a SandboxPython environment. An attacker can execute arbitrary code by exploiting this fallback mechanism. How to fix Arbitrary Code Injection? Upgrade | [,1.14.0a4) |
crewai-tools is a Set of tools for the crewAI framework Affected versions of this package are vulnerable to Exposed Dangerous Method or Function via the CodeInterpreter tool that fallbacks to SandboxPython when Docker is unreachable. An attacker can execute arbitrary code by invoking arbitrary C functions. Note: This issue affects users explicitly set How to fix Exposed Dangerous Method or Function? Upgrade | [,1.14.0a4) |