chiprook
← Security
SecurityOctober 4, 2026, 09:01

CVE-2026-37008: CrewAI sandbox bypassed without any import

MITRE published CVE-2026-37008 (CVSS 8.1) for CrewAI: the nine-name blocklist in SandboxPython is bypassed via ctypes.CDLL(None) and object-graph traversal without any import statement. All revisions before commit fb2323b are affected; the fix removed the feature instead of extending the list.

CVE-2026-37008: CrewAI sandbox bypassed without any import
#CrewAI
Read next
Security

CVE-2026-92957: vm2 sandbox escape via node: prefix bypass

Security

CVE-2026-92941: vm2 sandbox escape lets code hijack Node.js TLS trust store

Security

CVE-2026-92940: vm2 flaw lets sandboxed code steal tokens and hijack sockets

Security

vm2 CVE-2026-100721: path allowlist bypassed by prefix match