CVE-2026-37008: CrewAI sandbox bypassed without any import
MITRE published CVE-2026-37008 (CVSS 8.1) for CrewAI: the nine-name blocklist in SandboxPython is bypassed via ctypes.CDLL(None) and object-graph traversal without any import statement. All revisions before commit fb2323b are affected; the fix removed the feature instead of extending the list.
- CVSS 3.1 base score 8.1 HIGH, CWE-424, published Sept 13, 2026
- Nine-name blocklist bypassed via ctypes.CDLL(None) with no import
- All CrewAI revisions before commit fb2323b are affected
- Fix deleted SandboxPython rather than extending the blocklist
Read next
Security