CVE-2026-62240

HIGH

CrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools

Title source: cna
STIX 2.1

Description

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS rebinding techniques to access internal services and cloud metadata endpoints.

References (5)

Core 5
Core References
Release Notes release-notes patch
Release Notes
https://github.com/crewAIInc/crewAI/releases/tag/1.15.1
Exploit technical-description exploit issue-tracking
Researcher Disclosure
https://github.com/crewAIInc/crewAI/issues/6520
Issue Tracking issue-tracking patch
Pull Request
https://github.com/crewAIInc/crewAI/pull/6331

Scores

CVSS v3 7.4
EPSS 0.0031
EPSS Percentile 23.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
crewai/crewai < 1.15.1
crewAIInc/crewAI < 1.15.1
Published Jul 13, 2026
Tracked Since Jul 14, 2026