CVE-2026-62240
HIGHCrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools
Title source: cnaDescription
CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS rebinding techniques to access internal services and cloud metadata endpoints.
References (5)
Core 5
Core References
Release Notes release-notes
patch
Release Notes
https://github.com/crewAIInc/crewAI/releases/tag/1.15.1
Exploit technical-description
exploit
issue-tracking
Researcher Disclosure
https://github.com/crewAIInc/crewAI/issues/6520
Patch patch
Patch Commit
https://github.com/crewAIInc/crewAI/commit/5d4851eac797cafc45b726f65747fe2c9520fc42
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/crewai-ssrf-filter-bypass-via-http-redirect-in-scrape-tools
Scores
CVSS v3
7.4
EPSS
0.0031
EPSS Percentile
23.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (2)
crewai/crewai
< 1.15.1
crewAIInc/crewAI
< 1.15.1
Published
Jul 13, 2026
Tracked Since
Jul 14, 2026