CVE-2026-37008

Source
https://cve.org/CVERecord?id=CVE-2026-37008
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-37008.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-37008
Published
2026-09-13T00:00:00Z
Modified
2026-09-16T03:30:21Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L CVSS Calculator
Summary
[none]
Details

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying in any import statements. In other words, a within-process sandbox cannot merely account for the import system and instead must account for the complete runtime of the Python interpreter.

Database specific
{
    "cna_assigner": "mitre",
    "cwe_ids": [
        "CWE-424"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/37xxx/CVE-2026-37008.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "fb2323b3deb3ec62b3965526857e77a2264e4cd0"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "fb2323b3deb3ec62b3965526857e77a2264e4cd0"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "fb2323b"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/crewaiinc/crewai

Affected ranges

Type
GIT
Repo
https://github.com/crewaiinc/crewai
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

0.*
0.100.0
0.102.0
0.105.0
0.108.0
0.114.0
0.117.0
0.117.1
0.118.0
0.119.0
0.120.0
0.120.1
0.121.0
0.121.1
0.126.0
0.130.0
0.134.0
0.140.0
0.141.0
0.148.0
0.150.0
0.152.0
0.157.0
0.159.0
0.165.0
0.165.1
0.175.0
0.177.0
0.186.0
0.186.1
0.193.0
0.193.1
0.193.2
0.201.0
0.201.1
0.203.0
0.203.1
0.28.7
0.28.8
0.30.11
0.64.0
0.65.2
0.70.1
0.74.0
0.74.2
0.75.0
0.75.1
0.76.0
0.76.2
0.76.9
0.79.0
0.79.4
0.80.0
0.85.0
0.86.0
0.95.0
0.98.0
1.*
1.0.0
1.1.0
1.10.0
1.10.1
1.10.1a1
1.10.2a1
1.10.2rc1
1.10.2rc2
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
1.9.3
v0.*
v0.1.0
v0.1.1
v0.1.14
v0.1.2
v0.1.23
v0.1.32
v0.10.0
v0.11.0
v0.11.1
v0.11.2
v0.119.0
v0.14.0
v0.14.0rc0
v0.14.3
v0.14.4
v0.16.0
v0.16.3
v0.19.0
v0.22.0
v0.22.2
v0.22.4
v0.22.5
v0.27.0
v0.28.0
v0.28.1
v0.28.2
v0.28.5
v0.30.4
v0.30.5
v0.30.8
v0.32.0
v0.32.1
v0.32.2
v0.35.0
v0.35.3
v0.35.4
v0.35.5
v0.35.7
v0.35.8
v0.36.0
v0.41.0
v0.41.1
v0.5.0
v0.5.2
v0.5.3
v0.5.5
v0.51.0
v0.55.2
v0.60.0
v0.61.0
v0.63.0
v0.63.1
v0.63.2
v0.63.5
v0.63.6
v0.83.0
v1.*
v1.10.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-37008.json"