Junglewise Threat Intelligence

CVE-2026-62240: CrewAI SSRF filter bypass in scraping tools

CVE-2026-62240 · Severity: high · CVSS 7.4 · Published 2026-07-13

Technologies: crewai-tools (PyPI). Vendors: PyPI.

Executive brief

CrewAI's web scraping tools include a URL validator that checks if URLs are safe before fetching them, but only performs the validation once before following redirects. An attacker can supply a URL that initially appears safe but redirects to internal network addresses or cloud metadata endpoints, allowing unauthorized access to sensitive internal services and configuration data.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) bypass in the validate_url function of CrewAI's scraping toolset. The vulnerable component performs DNS resolution and blocklist checking on the initial URL but does not re-validate redirect targets, allowing attackers to chain a public-facing URL that redirects to restricted internal addresses (127.0.0.1, 169.254.169.254 cloud metadata, etc.) or use DNS rebinding techniques where a domain resolves differently on subsequent lookups. The attack vector is network-based with no authentication required and only passive user interaction (following a redirect). The fix (version 1.15.1 and later) implements a safe_get() helper that validates both the initial URL and every redirect target before following redirects, and restricts credential forwarding across origin boundaries.

Affected products

  • CrewAI crewai-tools < 1.15.1

Timeline

  • 2026-07-14: disclosed
  • 2026-06-26: patched: Fix merged in PR #6331; release 1.15.1 published 2026-06-27

References