ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability

AI summary · glm-5.3-flash

ZDI discloses unpatched unsafe reflection RCE vulnerability CVE-2026-92206 (CVSS 8.8) in the CrewAI agent framework.

Zero Day Initiative published ZDI-26-706, an unsafe reflection remote code execution vulnerability in the CrewAI framework, tracked as CVE-2026-92206 with a CVSS score of 8.8. Exploitation requires user interaction: the target must load a malicious agent configuration from the repository. As a 0day advisory, no patch is indicated at publication.

  • Unsafe reflection flaw allows remote code execution in CrewAI
  • CVE-2026-92206 rated CVSS 8.8
  • Exploitation requires loading a malicious agent configuration
  • Reported as a 0day via Zero Day Initiative

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-92206

NVD description · AI analysis pending
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must load a malicious agent configuration from the repository. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92206.

This source does not provide full text. Read it at zerodayinitiative.com.