CVE-2026-37007
A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://yerangamage.com/cves/detail/?slug=crewai-file-write, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/37xxx/CVE-2026-37007.json, https://nvd.nist.gov/vuln/detail/CVE-2026-37007, https://github.com/crewAIInc/crewAI/commit/713fa7d