{"id":"CVE-2026-62240","summary":"CrewAI \u003c 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools","details":"CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS rebinding techniques to access internal services and cloud metadata endpoints.","aliases":["GHSA-mr4r-hcgx-8p4h","PYSEC-2026-3819"],"modified":"2026-09-18T03:30:30.979974086Z","published":"2026-07-13T21:04:03.774Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62240.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62240.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62240"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/crewai-ssrf-filter-bypass-via-http-redirect-in-scrape-tools"},{"type":"REPORT","url":"https://github.com/crewAIInc/crewAI/issues/6520"},{"type":"FIX","url":"https://github.com/crewAIInc/crewAI/commit/5d4851eac797cafc45b726f65747fe2c9520fc42"},{"type":"FIX","url":"https://github.com/crewAIInc/crewAI/pull/6331"},{"type":"FIX","url":"https://github.com/crewAIInc/crewAI/releases/tag/1.15.1"},{"type":"PACKAGE","url":"https://github.com/crewAIInc/crewAI"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/crewaiinc/crewai","events":[{"introduced":"0"},{"fixed":"6491f5a6639c49ed1835520e683a4c42c3eaf634"},{"fixed":"5d4851eac797cafc45b726f65747fe2c9520fc42"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.15.1"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:crewai:crewai:*:*:*:*:*:*:*:*"}}],"versions":["1.15.1a1","1.15.0","1.14.8a5","1.14.8a4","1.14.8a3","1.14.8a2","1.14.8a1","1.14.8a","1.14.7","1.14.7rc2","1.14.7rc1","1.14.7a4","1.14.7a3","1.14.7a2","1.14.7a1","1.14.6","1.14.6a2","1.14.6a1","1.14.5","1.14.5a7","1.14.5a6","1.14.5a5","1.14.3a2","1.14.5a4","1.14.5a3","1.14.5a2","1.14.5a1","1.14.4","1.14.4a2","1.14.4a1","1.14.3","1.14.3a3","1.14.3a1","1.14.2","1.14.2rc1","1.14.2a5","1.14.2a4","1.14.2a3","1.14.2a2","1.14.2a1","1.14.1","1.14.1rc1","1.14.0","1.14.0a4","1.14.0a3","1.14.0a2","1.13.0","1.13.0a7","1.13.0a6","1.13.0a5","1.13.0a4","1.13.0a3","1.13.0rc1","1.13.0a2","1.12.0a2","1.13.0a1","1.12.2","1.12.1","1.12.0","1.12.0a3","1.12.0a1","1.11.1","1.11.0","1.11.0rc2","1.11.0rc1","1.10.2rc2","1.10.2rc1","1.10.2a1","1.10.1","1.10.1a1","1.10.0","v1.10.0.1","1.9.3","1.9.2","1.9.1","1.9.0","1.8.1","1.8.0","1.7.2","1.7.1","1.7.0","1.6.1","1.6.0","0.203.1","1.5.0","1.4.1","1.4.0","1.3.0","1.2.1","1.2.0","1.1.0","1.0.0","0.203.0","0.201.1","0.201.0","0.193.2","0.193.1","0.193.0","0.186.1","0.186.0","0.177.0","0.175.0","0.165.1","0.165.0","0.159.0","0.157.0","0.152.0","0.150.0","0.148.0","0.141.0","0.140.0","0.134.0","0.130.0","0.126.0","0.121.1","0.121.0","0.120.1","0.120.0","v0.119.0","0.119.0","0.118.0","0.117.1","0.117.0","0.114.0","0.108.0","0.105.0","0.102.0","0.100.0","0.98.0","0.95.0","0.86.0","0.85.0","v0.83.0","0.80.0","0.79.4","0.79.0","0.76.9","0.76.2","0.76.0","0.75.1","0.75.0","0.74.2","0.74.0","0.70.1","0.65.2","0.64.0","v0.63.6","v0.63.5","v0.63.2","v0.63.1","v0.63.0","v0.61.0","v0.60.0","v0.55.2","v0.51.0","v0.41.1","v0.41.0","v0.36.0","v0.35.8","v0.35.7","v0.35.5","v0.35.4","v0.35.0","v0.35.3","v0.32.2","v0.32.1","v0.32.0","0.30.11","v0.30.8","v0.30.5","v0.30.4","0.28.8","0.28.7","v0.28.5","v0.28.2","v0.28.1","v0.28.0","v0.27.0","v0.22.5","v0.22.4","v0.22.2","v0.22.0","v0.19.0","v0.16.3","v0.16.0","v0.14.4","v0.14.3","v0.14.0","v0.14.0rc0","v0.11.2","v0.11.1","v0.11.0","v0.10.0","v0.5.5","v0.5.3","v0.5.2","v0.5.0","v0.1.32","v0.1.23","v0.1.14","v0.1.2","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62240.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"}]}