{"id":"CVE-2026-37007","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-37007","summary":null,"details":"A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument.","published":"2026-08-27T00:00:00Z","modified":"2026-09-02T03:30:45.285656468Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/crewAIInc/crewAI/commit/713fa7d","label":"crewAIInc/crewAI@713fa7d"},"references":[{"type":"WEB","url":"https://yerangamage.com/cves/detail/?slug=crewai-file-write"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/37xxx/CVE-2026-37007.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-37007"},{"type":"FIX","url":"https://github.com/crewAIInc/crewAI/commit/713fa7d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-02T03:30:45.285656468Z"}}