CVE Watchtower β Back to CVE ListCVE-2026-2285NVDDescriptionCrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.Severity LevelHIGH (7.5)Published Date30/03/2026Last Modified06/04/2026Exploitation Status????Referenceshttps://www.kb.cert.org/vuls/id/221883