Four CVEs in CrewAI Enable Chaining Prompt Injection Into RCE, SSRF, and File Reads — Default Configurations Affected
Adversa AI·medium signal
Adversa AI's May 2026 roundup highlights four CVEs in CrewAI that allow attackers to chain prompt injection into remote code execution, server-side request forgery, and arbitrary file reads. The Code Interpreter and default configurations are affected. CrewAI is one of the most popular multi-agent frameworks (20K+ GitHub stars). For teams using CrewAI in production, this requires immediate patching and review of agent sandbox boundaries.