SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-37007

CRITICAL · CVSS 9.8 EPSS 0.69% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

FileWriterTool in crewai-tools versions up to 1.10.2rc1 is vulnerable to a path traversal attack, enabling remote attackers to execute arbitrary code by manipulating the filename argument. Organizations using this tool should prioritize patching or mitigating this vulnerability to prevent potential exploitation and ensure the security of their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-37007
Severity
CRITICAL
CVSS
9.8
EPSS
0.69%

Original NVD Description

A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument.