Executive brief
CrewAI's web scraping tools include a URL validator that checks if URLs are safe before fetching them, but only performs the validation once before following redirects. An attacker can supply a URL that initially appears safe but redirects to internal network addresses or cloud metadata endpoints, allowing unauthorized access to sensitive internal services and configuration data.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) bypass in the validate_url function of CrewAI's scraping toolset. The vulnerable component performs DNS resolution and blocklist checking on the initial URL but does not re-validate redirect targets, allowing attackers to chain a public-facing URL that redirects to restricted internal addresses (127.0.0.1, 169.254.169.254 cloud metadata, etc.) or use DNS rebinding techniques where a domain resolves differently on subsequent lookups. The attack vector is network-based with no authentication required and only passive user interaction (following a redirect). The fix (version 1.15.1 and later) implements a safe_get() helper that validates both the initial URL and every redirect target before following redirects, and restricts credential forwarding across origin boundaries.
Affected products
- CrewAI crewai-tools < 1.15.1
Timeline
- 2026-07-14: disclosed
- 2026-06-26: patched: Fix merged in PR #6331; release 1.15.1 published 2026-06-27
References
- https://github.com/crewAIInc/crewAI/issues/6520
- https://github.com/crewAIInc/crewAI/pull/6331
- https://github.com/crewAIInc/crewAI/commit/5d4851eac797cafc45b726f65747fe2c9520fc42
- https://github.com/crewAIInc/crewAI/releases/tag/1.15.1
- https://www.vulncheck.com/advisories/crewai-ssrf-filter-bypass-via-http-redirect-in-scrape-tools