NIXPKGS-2026-0866
GitHub issue
published on
by @mweinelt Activity log
- Created suggestion
-
@mweinelt
ignored
5 packages
- pkgsRocm.crewai
- python312Packages.crewai
- python313Packages.crewai
- python314Packages.crewai
- pkgsRocm.python3Packages.crewai
- @mweinelt accepted
- @mweinelt published on GitHub
CVE-2026-2285
CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.
References
Affected products
CrewAI
- ==1.0
Matching in nixpkgs
Ignored packages (5)
pkgs.pkgsRocm.crewai
Framework for orchestrating role-playing, autonomous AI agents
pkgs.python312Packages.crewai
Framework for orchestrating role-playing, autonomous AI agents
pkgs.python313Packages.crewai
Framework for orchestrating role-playing, autonomous AI agents
pkgs.python314Packages.crewai
Framework for orchestrating role-playing, autonomous AI agents
Package maintainers
-
@liberodark liberodark <liberodark@gmail.com>