42
47
47
47
47
42
42
42
42
42
47
47
42
47
42
ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability
ZDI discloses unpatched unsafe reflection RCE vulnerability CVE-2026-92206 (CVSS 8.8) in the CrewAI agent framework.
Zero Day Initiative published ZDI-26-706, an unsafe reflection remote code execution vulnerability in the CrewAI framework, tracked as CVE-2026-92206 with a CVSS score of 8.8. Exploitation requires user interaction: the target must load a malicious agent configuration from the repository. As a 0day advisory, no patch is indicated at publication.
50
42
42
42
42
42
42
42
42
42
47
42
42
42
42
47
47
42
42
57
42
47
42
47
42